Select your language

WHAT ARE YOU LOOKING FOR?

Popular Tags

Raleigh, NC

32°F
Clear Sky Humidity: 79%
Wind: 1.95 M/S

Attackers Exploit N-central Flaw to Reach Managed Devices, Prompting N-able Hotfix 2

Attackers Exploit N-central Flaw to Reach Managed Devices, Prompting N-able Hotfix 2

N-able has issued a new set of security hotfixes for its N-central Remote Monitoring and Management (RMM) platform as part of its ongoing response to active exploitation of a recently discovered vulnerability affecting the product.

The company emphasized that the latest update is mandatory, even for customers who previously installed the initial security patch.

“Hotfix 2 replaces Hotfix 1 and introduces additional hardening measures designed to strengthen protections for both service providers and their customers,” N-able said.

Attack Investigation Reveals Active Exploitation

The latest update follows an investigation that began after N-able detected suspicious activity within a customer environment on July 31, 2026. The investigation ultimately uncovered active exploitation of a previously unknown zero-day vulnerability in N-central, tracked as CVE-2026-18577 and assigned a CVSS score of 8.2.

The flaw affects all vulnerable N-central versions released prior to 2026.3.1.7.

Researchers determined that CVE-2026-18577 resulted from an incomplete remediation of an earlier authentication-bypass vulnerability, CVE-2026-18556, which carries the same severity rating. Both vulnerabilities allow attackers to circumvent authentication controls and seize control of user accounts within affected deployments.

The vulnerabilities have since been added to CISA's list of actively exploited security flaws.

Attackers Leveraged N-central to Reach Managed Systems

According to N-able, threat actors successfully exploited the vulnerability to gain remote administrative access to vulnerable N-central servers.

After obtaining control of the management platform, attackers abused the built-in Take Control remote-access functionality to connect to devices managed through the affected N-central environment.

The compromise extended beyond the management server itself.

Once attackers reached managed endpoints, they installed persistence mechanisms intended to survive remediation efforts. One observed technique involved creating a new service that leveraged Cloudflare Tunnel, a legitimate networking tool often abused by threat actors to establish covert communication channels and maintain access to compromised systems.

This allowed attackers to retain access to endpoints even after defenders removed their access to the original N-central server.

Limited Number of Customers Impacted

N-able confirmed that only a limited number of customer environments have been affected so far. However, the company continues to monitor the situation and expand defensive measures as attackers modify their tactics.

Organizations running on-premises versions of N-central have been instructed to upgrade immediately to version 2026.3.1.10, which includes the latest protections.

Expanded Indicators of Compromise Released

As part of its ongoing investigation, N-able has published an updated list of IP addresses associated with suspicious activity and potential attacker infrastructure:

  • 173.249.252[.]176
  • 173.249.252[.]200
  • 185.156.46[.]150
  • 23.234.94[.]43
  • 37.153.90[.]88
  • 37.19.210[.]32
  • 68.235.46[.]214
  • 68.235.46[.]235
  • 87.249.138[.]34
  • 92.118.112[.]181

Security teams are encouraged to review network logs, endpoint telemetry, and authentication records for connections involving these addresses.

New Automated Detection Tool Available

To assist customers, N-able has also released a customized service template that automatically scans Windows endpoints managed through N-central for known indicators of compromise.

However, the company cautioned that the absence of detected indicators should not be interpreted as proof that an environment is unaffected.

According to N-able, threat investigations remain ongoing and additional indicators may emerge as research continues.

Recommended Next Steps

In addition to applying the latest hotfixes, organizations should:

  • Upgrade N-central to the latest supported version immediately.
  • Review Take Control activity logs for unauthorized sessions.
  • Investigate systems for Cloudflare Tunnel services and unexpected persistence mechanisms.
  • Examine authentication and administrative access records.
  • Rotate privileged credentials if compromise is suspected.
  • Conduct proactive threat hunting across managed endpoints.
  • Monitor for communications with known malicious infrastructure.

Ongoing Security Concern for RMM Platforms

The incident highlights the continued attractiveness of Remote Monitoring and Management platforms as targets for threat actors. Because RMM solutions provide centralized access to numerous systems, successful compromise can give attackers a direct pathway into entire customer environments.

With evidence that attackers moved from vulnerable N-central servers into managed endpoints and established persistent access mechanisms, organizations are being urged to treat this issue as a high-priority security event and conduct thorough investigations beyond simply applying patches.

Found this article interesting? Follow us on X(Twitter) ,Threads and FaceBook to read more exclusive content we post. 

Cybersecurity Insight delivers timely updates on global cybersecurity developments, including recent system breaches, cyber-attacks, advancements in artificial intelligence (AI), and emerging technology innovations. Our goal is to keep viewers well-informed about the latest trends in technology and system security, and how these changes impact our lives and the broader ecosystem

Please fill the required field.