Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-10 ยท updated: 2026-08-10 ยท tags: [incident, rmm, exploit, n-central, nable, supply-chain] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: true

N-able Issues N-central Hotfix 2

N-able released a required second hotfix for N-central, superseding Hotfix 1 with additional hardening, as threat actors continue exploiting CVE-2026-18577 (CVSS 8.2) in the RMM product. The company detected unusual activity in a customer's environment on 31 July, leading to discovery of an exploited zero-day impacting N-central server versions prior to 2026.3.1.7.

Attribute Detail
CVE CVE-2026-18577 (CVSS 8.2)
Fix N-central Hotfix 2 (supersedes Hotfix 1)
Detection Unusual activity in a customer environment, 31 July 2026
Affected N-central servers prior to 2026.3.1.7
Status Attackers reaching managed systems and persisting
Source BleepingComputer โ€” Tier 2/4

N-able states Hotfix 2 is required even if the earlier hotfix was applied, reflecting continued monitoring of adversaries as they evolve techniques. A compromised N-central RMM server grants attackers the same elevated access legitimate technicians use โ€” a first-order concern for Australian and NZ MSPs.

Related Pages

Source