Critical

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

Help Net Security
Actively Exploited

Overview

N-able has released a second hotfix for its N-central remote monitoring and management solution due to ongoing exploitation of the vulnerability identified as CVE-2026-18577. This new hotfix, referred to as Hotfix 2, is critical even for those who have already applied the first hotfix, as it includes additional security measures aimed at protecting users and their customers from active attacks. The company has also shared indicators of compromise that have been observed in these attacks, highlighting the seriousness of the situation. Managed service providers using N-central should prioritize applying this hotfix to enhance their defenses against these threats and protect their clients' systems.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: N-central monitoring and management solution by N-able
  • Action Required: Apply N-able Hotfix 2 for N-central, which includes additional hardening measures beyond those in Hotfix 1.
  • Timeline: Ongoing since the discovery of CVE-2026-18577

Original Article Summary

To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs). “Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers,” the company said, and shared additional indicators of compromise observed in attacks. A second hotfix to “expand protections” Earlier this … More → The post N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 appeared first on Help Net Security.

Impact

N-central monitoring and management solution by N-able

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since the discovery of CVE-2026-18577

Remediation

Apply N-able Hotfix 2 for N-central, which includes additional hardening measures beyond those in Hotfix 1.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.