N‑central Security Update – August 6, 2026

As our investigation into the recent N‑central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.

This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.

Hotfix Details: 2026.3.1.10 https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/

Background

On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment, leading to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server. We immediately mobilized our engineering and security teams, notified customers, and began investigating the full scope of the issue. As our investigation progressed, we determined the vulnerability affected all versions of N‑central and released a comprehensive hotfix (2026.3.1.7) on August 2: N‑central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577.

As our investigation into the recent N‑central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques, and we released a new hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.

Hotfix Details: 2026.3.1.10 https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/

What you need to do

The attack

As we performed our analysis, we determined that an attacker had identified a vulnerability on all N‑central servers running a version prior to 2026.3.1.7, which allowed them to obtain administrative access remotely. Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment. Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.

As our investigation into the recent N‑central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.

The impact

A limited number of customers have been identified as impacted, and N‑able support has directly engaged with each of them. Our investigation is ongoing. If you are not running the most recent version of N‑central, we strongly encourage you to upgrade immediately.

Indicators

N‑able has identified the following IP addresses being used in this attack:

173[.]249[.]252[.]176
173[.]249[.]252[.]200
185[.]156[.]46[.]150
23[.]234[.]94[.]43
37[.]153[.]90[.]88
37[.]19[.]210[.]32
68[.]235[.]46[.]214
68[.]235[.]46[.]235
87[.]249[.]138[.]34
92[.]118[.]112[.]181

Additional indicators will be shared as they become available.

CVE Public Links: CVE-2026-18577

For indicators of compromise, N‑able has released a custom service template that provides an automated way to check for known indicators of compromise on your Windows device endpoints in N‑central. You can download the service templates here: https://developer.n-able.com/n-central/recipes/cve-2026-18577-detection

Please note that this tool checks only for the specific indicators currently known to be associated with this attack. A clean result should not be interpreted as a guarantee that your environment has not been impacted. Our investigation is ongoing and additional indicators may be identified over time. We strongly recommend this be used as one layer of your assessment, alongside a thorough review of your environment, logs, and account activity.

Security best practices

This incident is a reminder of how critical regular patching and strong security hygiene are in protecting your environment. Despite rigorous development and security practices, no software is immune to vulnerabilities, which is why a proactive security posture is essential. Many successful attacks exploit known vulnerabilities in outdated software, and staying current is one of your most effective defenses. We strongly encourage all customers to prioritize patching, enforce multi-factor authentication, routinely audit user access, and monitor for unusual activity in their environments.

© N‑able Solutions ULC und N‑able Technologies Ltd. Alle Rechte vorbehalten.

Dieses Dokument dient nur zu Informationszwecken und stellt keine Rechtsberatung dar. N‑able übernimmt weder ausdrücklich noch stillschweigend Gewähr noch Haftung oder Verantwortung für Korrektheit, Vollständigkeit oder Nutzen der in diesem Dokument enthaltenen Informationen.

N-ABLE, N-CENTRAL und andere Marken und Logos von N‑able sind ausschließlich Eigentum von N‑able Solutions ULC und N‑able Technologies Ltd. Sie sind gesetzlich geschützte Marken und möglicherweise beim Patent- und Markenamt der USA und in anderen Ländern registriert oder zur Registrierung angemeldet. Alle anderen hier genannten Marken dienen ausschließlich zu Informationszwecken und sind Marken (oder registrierte Marken) der entsprechenden Unternehmen.