type: incident ยท created: 2026-08-10 ยท updated: 2026-08-10 ยท tags: [incident, rmm, exploit, n-central, nable, supply-chain] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: true
N-able Issues N-central Hotfix 2
N-able released a required second hotfix for N-central, superseding Hotfix 1 with additional hardening, as threat actors continue exploiting CVE-2026-18577 (CVSS 8.2) in the RMM product. The company detected unusual activity in a customer's environment on 31 July, leading to discovery of an exploited zero-day impacting N-central server versions prior to 2026.3.1.7.
| Attribute | Detail |
|---|---|
| CVE | CVE-2026-18577 (CVSS 8.2) |
| Fix | N-central Hotfix 2 (supersedes Hotfix 1) |
| Detection | Unusual activity in a customer environment, 31 July 2026 |
| Affected | N-central servers prior to 2026.3.1.7 |
| Status | Attackers reaching managed systems and persisting |
| Source | BleepingComputer โ Tier 2/4 |
N-able states Hotfix 2 is required even if the earlier hotfix was applied, reflecting continued monitoring of adversaries as they evolve techniques. A compromised N-central RMM server grants attackers the same elevated access legitimate technicians use โ a first-order concern for Australian and NZ MSPs.
Related Pages
- Cve 2026 18577 Nable Ncentral Auth Bypass โ the underlying flaw
- N Able Patches Max Severity N Central Flaw Amid Ongoing Attacks โ the later Hotfix 4 / CVE-2026-86218