N‑central Security Update – August 2, 2026

Yesterday, N‑able posted an advisory to our Uptime Page regarding exploitation against our N‑central platform in response to a security issue affecting customers running versions of N‑central prior to 2026.2. We had addressed this issue in later builds and were recommending that customers on older versions upgrade to version 2026.3 as an immediate protective measure. As our investigation continued, we identified an alternative method to exploit this vulnerability, which was not mitigated in our previous fix. This resulted in a hotfix for 2026.3, which was released this afternoon: https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/

Background

On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not uncommon, but the volume was high and the engineering and security teams were engaged. On the morning of August 2, 2026 our analysis of a previously addressed vulnerability (CVE-2026-18556), which was fixed in 2026.2, exposed another vector to exploit this vulnerability. Our engineering team immediately developed a fix, which is available now to all customers. We’ve also released a new CVE for this finding, which is being released under CVE-2026-18577.

The attack

As we performed our analysis, we determined that an attacker had identified a vulnerability on all N‑central servers running a version prior to 2026.3.1.7, which allowed them to obtain administrative access remotely. Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment. Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.

The impact

A limited number of customers have been identified to be impacted by this, and, for those impacted customers, N‑able support has directly engaged. If you’re a customer who is not running the most recent version of N‑central, we strongly encourage you to upgrade to 2026.3.1.7.

Indicators

N‑able had identified the following IP addresses being used in this attack:

173[.]249[.]252[.]200
87[.]249[.]138[.]34
37[.]19[.]210[.]32
37[.]153[.]90[.]88
92[.]118[.]112[.]181
68[.]235[.]46[.]214

Additional indicators will be shared as they become available.

CVE Public Link here: CVE-2026-18577

Security best practices

This incident is a reminder of how critical regular patching and strong security hygiene are in protecting your environment. Despite rigorous development and security practices, no software is immune to vulnerabilities, which is why a proactive security posture is essential. Many successful attacks exploit known vulnerabilities in outdated software, and staying current is one of your most effective defenses. We strongly encourage all customers to prioritize patching, enforce multi-factor authentication, routinely audit user access, and monitor for unusual activity in their environments.

© N‑able Solutions ULC y N‑able Technologies Ltd. Todos los derechos reservados.

Este documento solo se proporciona con fines informativos. No debe utilizarse para obtener orientación legal. N‑able no ofrece ninguna garantía, implícita o explícita, ni asume ninguna responsabilidad legal o jurídica por la exactitud, integridad o utilidad de cualquier información contenida en este documento.

N-ABLE, N-CENTRAL y otras marcas comerciales y logotipos de N‑able son propiedad exclusiva de N‑able Solutions ULC y N‑able Technologies Ltd., y pueden ser marcas sujetas al derecho anglosajón, estar registradas o pendientes de registro en la Oficina de Patentes y Marcas de Estados Unidos o en otros países. El resto de marcas comerciales mencionadas en este documento solo se utilizan con fines de identificación y son marcas comerciales (o marcas comerciales registradas) de sus respectivas empresas.