N‑central Security Update – August 4, 2026
Background
On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment which led to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server. We immediately mobilized our engineering and security teams, notified customers, and began investigating the full scope of the issue. As our investigation progressed, we determined the vulnerability affected all versions of N‑central and released a comprehensive hotfix (2026.3.1.7) on August 2: N‑central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577. We have been communicating directly with customers throughout and continue to actively support those working to get protected.
We’ve also released a new CVE for this finding, which is being released under CVE-2026-18577. The upgrade covers CVE-2026-18577 and CVE-2026-18556. Please be sure to subscribe to N‑able Uptime and Release Notes for ongoing product notifications if you are not already subscribed.
The attack
As we performed our analysis, we determined that an attacker had identified a vulnerability on all N‑central servers running a version prior to 2026.3.1.7, which allowed them to obtain administrative access remotely. Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment. Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.
The impact
A limited number of customers have been identified to be impacted by this, and, for those impacted customers, N‑able support has directly engaged. If you’re a customer who is not running the most recent version of N‑central, we strongly encourage you to upgrade to 2026.3.1.7.
Indicators
N‑able had identified the following IP addresses being used in this attack:
173[.]249[.]252[.]176
173[.]249[.]252[.]200
185[.]156[.]46[.]150
23[.]234[.]94[.]43
37[.]153[.]90[.]88
37[.]19[.]210[.]32
68[.]235[.]46[.]214
68[.]235[.]46[.]235
87[.]249[.]138[.]34
92[.]118[.]112[.]181
Additional indicators will be shared as they become available.
CVE Public Link here: CVE-2026-18577
For indicators of compromise, N‑able has released a custom service template that provides an automated way to check for known indicators of compromise on your Windows device endpoints in N‑central. You can download the service templates here: https://developer.n-able.com/n-central/recipes/cve-2026-18577-detection
Please note that this tool checks only for the specific indicators currently known to be associated with this attack. A clean result should not be interpreted as a guarantee that your environment has not been impacted. Our investigation is ongoing and additional indicators may be identified over time. We strongly recommend this be used as one layer of your assessment, alongside a thorough review of your environment, logs, and account activity.
Security best practices
This incident is a reminder of how critical regular patching and strong security hygiene are in protecting your environment. Despite rigorous development and security practices, no software is immune to vulnerabilities, which is why a proactive security posture is essential. Many successful attacks exploit known vulnerabilities in outdated software, and staying current is one of your most effective defenses. We strongly encourage all customers to prioritize patching, enforce multi-factor authentication, routinely audit user access, and monitor for unusual activity in their environments.
© N‑able Solutions ULC y N‑able Technologies Ltd. Todos los derechos reservados.
Este documento solo se proporciona con fines informativos. No debe utilizarse para obtener orientación legal. N‑able no ofrece ninguna garantía, implícita o explícita, ni asume ninguna responsabilidad legal o jurídica por la exactitud, integridad o utilidad de cualquier información contenida en este documento.
N-ABLE, N-CENTRAL y otras marcas comerciales y logotipos de N‑able son propiedad exclusiva de N‑able Solutions ULC y N‑able Technologies Ltd., y pueden ser marcas sujetas al derecho anglosajón, estar registradas o pendientes de registro en la Oficina de Patentes y Marcas de Estados Unidos o en otros países. El resto de marcas comerciales mencionadas en este documento solo se utilizan con fines de identificación y son marcas comerciales (o marcas comerciales registradas) de sus respectivas empresas.