N‑central Security Update – August 10, 2026
We know the last week and a half hasn’t been easy. Patch notifications, urgent emails, and open questions take a real toll on your team, your customers, and your confidence in the tools you rely on. In moments like this, everyone wants the same thing: real information, fast. That’s what we’re focused on, giving you as much detail as we can, as rapidly, transparently, and safely as possible, so you always have a clear picture of where things stand.
What happened: how we found it
On July 31, our Adlumin MDR solution detected unusual activity inside a customer environment and identified a threat actor actively exploiting a previously unknown vulnerability in N‑central. We want to be straightforward about this: we detected this ourselves, in real time. That matters, not because we want recognition for it, but because it is evidence that layered, continuous security monitoring works. It is also the reason we were able to respond as quickly as we did.
Once identified, our engineering and security teams mobilized immediately. We published guidance the same day, registered CVE-2026-18556, and released Hotfix 1 (2026.3.1.7) on August 2, and registered CVE-2026-18577. When continued monitoring on August 6 surfaced a related attack path, we released Hotfix 2 (2026.3.1.10) the same day with additional hardening measures that build on and supersede Hotfix 1.
Our support team is prioritizing upgrade assistance. If you need help, please reach out at me.n-able.com and we will be there.
The attack
A threat actor exploited a vulnerability in N‑central that allowed remote administrative access without authentication. Once inside, they used N‑central’s Take Control feature to connect to managed devices, and registered Cloudflare tunnel services on those devices to maintain persistence even after their access to N‑central was revoked. Hotfix 1 addressed the original access point. Continued monitoring identified a related attack path, which Hotfix 2 addresses with additional hardening.
The impact
A limited number of customers have been identified as impacted, and our team has directly engaged with each of them. If you have heard from us, you have a dedicated point of contact and we are with you. Our investigation remains active and ongoing and we are not calling this closed until we are fully confident in that conclusion.
On transparency: what we can and can’t share right now
We hear you. The desire for more detail, especially technical specifics, is completely understandable, and you deserve a straight answer about why we haven’t shared more.
We are also aware that some of you have seen technical details and commentary circulating from third parties. We understand that can be frustrating when it feels like others are saying more than we are. Our deliberate focus throughout this incident has been on providing the facts our customers need to protect their environments—not speculating on attack vectors or amplifying information that we cannot fully verify. Sharing unconfirmed technical details, even with good intentions, can give threat actors useful information and create confusion that makes it harder, not easier, for you to respond.
Releasing specific technical details while threat actors are still active also gives them information they can use. We made a deliberate decision to protect our customers first and explain later. A full root cause analysis is coming, and we will share it as soon as it is safe to do so.
What we can commit to in the meantime: regular updates, even when the news is simply that our investigation is continuing. A gap in communication should never be mistaken for a gap in effort. Our teams are working around the clock.
You are part of this
Many of you acted quickly: applying patches, reviewing your environments, flagging concerns, and holding us accountable. That matters more than you know. You are not just our customers; you are part of our extended security team. The businesses you protect depend on both of us, and we do not take that lightly.
This kind of security event tests partnerships. We believe transparency, speed, and standing behind our customers when it is hard are what define our partnership with you. We intend to keep earning that trust.
Timeline: what happened
- Jul 31 Adlumin MDR detects unusual activity; threat actor identified. Response team engaged immediately.
- Aug 1 First public guidance issued; upgrade recommendation posted. First CVE registered.
- Aug 2 Second CVE registered. Hotfix 1 (2026.3.1.7) released and mitigation deployed to hosted environments. Customers notified directly.
- Aug 6 Related attack path identified through continued monitoring. Hotfix 2 (2026.3.1.10) released same day and mitigation deployed to hosted environments. Customers notified directly.
- Ongoing Investigation, hardening, and direct customer support continues.
If you delayed upgrading, please read this carefully
Applying Hotfix 2 closes the vulnerability that allowed attackers in, but it does not remove a threat actor who may already be present in your environment. For customers who have waited to patch, it is critical to understand that during that window, attackers have been observed creating new accounts and resetting existing ones to maintain persistence. Upgrading is an essential first step, but it is not the last one. If you applied either hotfix more than a few days after it was released, you should treat your environment as potentially compromised and conduct a thorough review of all user accounts, access privileges, and activity—regardless of what our IOC scanning tool returns. If you find anything unusual or need assistance with that review, please contact our support team immediately at me.n-able.com.
Indicators of compromise
- A file named «svchost.exe» in a user’s Documents directory
- A registered service named «Cloudflared»
- Unusual Take Control activity or unauthorized actions on managed endpoints
- Suspicious logins to your N‑central server
- Unexpected creation of new users
- Unexplained user password resets
- Traffic from the following IP addresses:
73[.]249[.]252[.]200
185[.]156[.]46[.]150
23[.]234[.]94[.]43
37[.]153[.]90[.]88
37[.]19[.]210[.]32
68[.]235[.]46[.]214
68[.]235[.]46[.]235
87[.]249[.]138[.]34
92[.]118[.]112[.]181
Additional indicators will be shared as they become available. CVE: CVE-2026-18577
A custom service template is available to scan for known indicators of compromise across Windows endpoints in N‑central. Download here: https://developer.n-able.com/n-central/recipes/cve-2026-18577-detection
Please note this tool checks only for currently known indicators. A clean result is not a guarantee that your environment was not impacted. Use it as one layer of your assessment alongside a thorough review of logs, accounts, and activity in your environment.
What we ask of you
- Stay current. Apply Hotfix 2 (2026.3.1.10) if you haven’t. Download here.
- Enforce MFA across all accounts.
- Unless required for an open support issue, disable your in-product support account as a best practice.
- Audit user access and look for anything unfamiliar.
- Monitor your environment and treat our published indicators (above) as a starting point, not a complete picture.
No software is immune to vulnerabilities. That is the reality of the world we all operate in. What separates organizations that weather these moments from those that don’t is preparation, speed, and the strength of the partnerships around them. We are committed to being that partner for you.
Resources
- For assistance: me.n-able.com
- Status and updates: uptime.n-able.com
- CVE details: CVE-2026-18577
© N‑able Solutions ULC y N‑able Technologies Ltd. Todos los derechos reservados.
Este documento solo se proporciona con fines informativos. No debe utilizarse para obtener orientación legal. N‑able no ofrece ninguna garantía, implícita o explícita, ni asume ninguna responsabilidad legal o jurídica por la exactitud, integridad o utilidad de cualquier información contenida en este documento.
N-ABLE, N-CENTRAL y otras marcas comerciales y logotipos de N‑able son propiedad exclusiva de N‑able Solutions ULC y N‑able Technologies Ltd., y pueden ser marcas sujetas al derecho anglosajón, estar registradas o pendientes de registro en la Oficina de Patentes y Marcas de Estados Unidos o en otros países. El resto de marcas comerciales mencionadas en este documento solo se utilizan con fines de identificación y son marcas comerciales (o marcas comerciales registradas) de sus respectivas empresas.