CVE Tools

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

The Hacker NewsBy The Hacker News

Reported exploitedN-able N-central

Our summary

N-able has issued another round of hotfixes for its N-central product following the detection of active exploitation attempts targeting a newly disclosed vulnerability, CVE-2026-18577. This zero-day flaw allows attackers to bypass authentication and gain remote administrative access, which has been used in real-world attacks since July 31, 2026. Affected versions are all prior to 2026.3.1.7, and users are urged to apply Hotfix 2 immediately—even if they previously installed Hotfix 1—as it includes critical additional protections. The company also recommends reviewing internal systems for signs of compromise using the provided IoCs and service templates.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store