N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
N-able, a security vendor, has confirmed that attackers have successfully exploited a zero-day vulnerability, CVE-2026-18577, in their N-central remote monitoring and management platform. The security flaw allows an unauthenticated attacker to gain administrative access to remote servers. Following the first hotfix released on August 2, N-able has pushed out a second mandatory hotfix, Hotfix 2, version 2026.3.1.10, just days after the first.
The second update is meant to further harden the platform as they continue to monitor threat actors evolving their attack techniques. The affected N-central servers are those running versions prior to 2026.3.1.7, and the exploitation was first detected by N-able's Adlumin managed detection and response service on July 31. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, providing U.S. federal agencies a three-day deadline to address the issue.
N-able has identified ten IP addresses associated with the attacks and released a service template for customers to detect indicators of compromise on Windows endpoints. Despite the disclosure, the vendor is warning customers to not rely solely on clean scans as an all-clear, as additional indicators may emerge as they continue their investigation.
Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.