N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
N-able, a vendor of remote monitoring and management platforms, has confirmed that attackers have exploited a zero-day vulnerability, CVE-2026-18577, to gain administrative access to customer networks. This occurred just days after the vendor issued a first mandatory hotfix. The attackers remotely exploited vulnerable N-central servers and used the Take Control feature to connect to systems managed through N-central.
They then registered a new Cloudflare Tunnel service to maintain their presence within the compromised systems. N-able is yet to disclose the exact number of affected customers, downstream systems reached, or the actions taken by the attackers after establishing persistent access. However, the vendor has released Hotfix 2, version 2026.3.1.10, mandating installation for all N-central on-premises customers, including those who had previously installed the first emergency fix.
The company warns that Hotfix 2 is required, even if the earlier hotfix has been applied. The vulnerability affects N-central servers running versions prior to 2026.3.1.7, and hosted environments have already received the latest mitigations.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.