Hackers are targeting a newly disclosed zero-day vulnerability in a widely used remote monitoring and management platform, N-central.
The platform’s developer, N-able, disclosed both the vulnerability and its exploitation in an August 3 blog post, warning that it impacted all versions of N-central.
“On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment which led to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server,” N-able said earlier this week.
“We immediately mobilised our engineering and security teams, notified customers, and began investigating the full scope of the issue.”
N-able has since been working directly with its customers and has issued a hotfix.
The vulnerability – CVE-2026-18577 – could allow (and is allowing, apparently) a remote unauthenticated attacker to bypass authentication and gain administrative control of vulnerable N-central servers.
According to cyber security firm Rapid7, N-central is used by enterprise IT teams and managed service providers to manage servers, workstations, and other remote assets.
“Because the platform operates with extensive administrative privileges across customer environments, successful compromise of an N-central server can provide attackers with an efficient path to compromise downstream managed systems,” Rapid7 said in an August 4 blog post.
N-able went into more detail regarding the malicious activity it had observed once the attacker had gained administrative access.
“Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment,” N-able said.
“Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.”
As of August 3, only a “limited number” of N-able’s customers had been impacted, and they are being supported.
The issue has been addressed in N-able N-central 2026.3.1 Hotfix 1 (2026.3.1.7), and the company also recommends the following actions:
- Upgrade N-central agents after applying the server hotfix.
- Review systems for indicators of compromise.
- Contact N-able Support immediately if evidence of compromise is discovered.
- Engage internal incident response teams if malicious activity is identified.
“This incident is a reminder of how critical regular patching and strong security hygiene are in protecting your environment,” N-able said.
“Despite rigorous development and security practices, no software is immune to vulnerabilities, which is why a proactive security posture is essential.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.