N‑central Security Update – August 4, 2026

Background

On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment which led to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server. We immediately mobilized our engineering and security teams, notified customers, and began investigating the full scope of the issue. As our investigation progressed, we determined the vulnerability affected all versions of N‑central and released a comprehensive hotfix (2026.3.1.7) on August 2: N‑central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577. We have been communicating directly with customers throughout and continue to actively support those working to get protected.

We’ve also released a new CVE for this finding, which is being released under CVE-2026-18577. The upgrade covers CVE-2026-18577 and CVE-2026-18556. Please be sure to subscribe to N‑able Uptime and Release Notes for ongoing product notifications if you are not already subscribed.

The attack

As we performed our analysis, we determined that an attacker had identified a vulnerability on all N‑central servers running a version prior to 2026.3.1.7, which allowed them to obtain administrative access remotely. Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment. Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.

The impact

A limited number of customers have been identified to be impacted by this, and, for those impacted customers, N‑able support has directly engaged. If you’re a customer who is not running the most recent version of N‑central, we strongly encourage you to upgrade to 2026.3.1.7.

Indicators

N‑able had identified the following IP addresses being used in this attack:

173[.]249[.]252[.]176
173[.]249[.]252[.]200
185[.]156[.]46[.]150
23[.]234[.]94[.]43
37[.]153[.]90[.]88
37[.]19[.]210[.]32
68[.]235[.]46[.]214
68[.]235[.]46[.]235
87[.]249[.]138[.]34
92[.]118[.]112[.]181

Additional indicators will be shared as they become available.

CVE Public Link here: CVE-2026-18577

For indicators of compromise, N‑able has released a custom service template that provides an automated way to check for known indicators of compromise on your Windows device endpoints in N‑central. You can download the service templates here: https://developer.n-able.com/n-central/recipes/cve-2026-18577-detection

Please note that this tool checks only for the specific indicators currently known to be associated with this attack. A clean result should not be interpreted as a guarantee that your environment has not been impacted. Our investigation is ongoing and additional indicators may be identified over time. We strongly recommend this be used as one layer of your assessment, alongside a thorough review of your environment, logs, and account activity.

Security best practices

This incident is a reminder of how critical regular patching and strong security hygiene are in protecting your environment. Despite rigorous development and security practices, no software is immune to vulnerabilities, which is why a proactive security posture is essential. Many successful attacks exploit known vulnerabilities in outdated software, and staying current is one of your most effective defenses. We strongly encourage all customers to prioritize patching, enforce multi-factor authentication, routinely audit user access, and monitor for unusual activity in their environments.

© N‑able Solutions ULC e N‑able Technologies Ltd. Todos os direitos reservados.

Este documento é fornecido apenas para fins informativos e não deve servir de base para aconselhamento jurídico. A N‑able não oferece nenhuma garantia, expressa ou implícita, nem assume qualquer responsabilidade legal ou responsabilidade pela precisão, integralidade ou utilidade de qualquer informação nele contido.

As marcas N-ABLE, N-CENTRAL e outras marcas registradas e logotipos N‑able são de propriedade exclusiva da N‑able Solutions ULC e da N‑able Technologies Ltd e podem ser marcas legais comuns, registradas ou de registro pendente com o Escritório de Marcas e Patentes dos EUA e com outros países. Todas as outras marcas comerciais mencionadas neste documento são usadas apenas para fins de identificação e são marcas comerciais (e poderão ser marcas registradas) de suas respectivas empresas.