Hackers are actively targeting a newly disclosed zero-day in the N-central remote monitoring and management platform, N‑able said, and the company has released a hotfix.
N‑able disclosed both the vulnerability and its exploitation in a 3 August blog post, warning that it impacted all versions of N-central. The flaw, tracked as CVE-2026-18577, “could allow (and is allowing, apparently) a remote unauthenticated attacker to bypass authentication and gain administrative control of vulnerable N-central servers,” the company said.
N-central exploitation and observed activity
“On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment which led to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server,” N‑able said. “We immediately mobilised our engineering and security teams, notified customers, and began investigating the full scope of the issue.”
According to Rapid7, N-central is used by enterprise IT teams and managed service providers to manage servers, workstations, and other remote assets. “Because the platform operates with extensive administrative privileges across customer environments, successful compromise of an N-central server can provide attackers with an efficient path to compromise downstream managed systems,” Rapid7 said in a 4 August blog post.
N‑able described the attacker’s post-exploitation actions: “Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment.” “Once on those devices, the attackers registered a new service for a Cloudflare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.” As of 3 August, only a “limited number” of customers had been impacted and were being supported.
Mitigation and recommendations
N‑able has issued a patch: the issue is addressed in N-able N-central 2026.3.1 Hotfix 1 (2026.3.1.7). The company recommends the following actions: upgrade N-central agents after applying the server hotfix; review systems for indicators of compromise; contact N-able Support immediately if evidence of compromise is discovered; and engage internal incident response teams if malicious activity is identified.
“This incident is a reminder of how critical regular patching and strong security hygiene are in protecting your environment,” N‑able said. “Despite rigorous development and security practices, no software is immune to vulnerabilities, which is why a proactive security posture is essential.”

