N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
Our summary
N-able has issued a second security hotfix, version 2026.3.1.10, for its N-central Remote Monitoring and Management platform to address ongoing exploitation of CVE-2026-18577. This update supersedes the earlier Hotfix 1 (version 2026.3.1.7) and introduces additional hardening measures against a threat actor who successfully bypassed previous patches. Attackers are using the vulnerability to gain unauthorized access to managed endpoints, establish persistence via CloudFlare tunnels, and disable security software.
Help Net Security publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.