N-able Confirms Attackers Reached Customer Networks via N-central Zero-Day
IT management vendor N-able has confirmed that attackers exploiting a critical zero-day vulnerability in its N-central platform successfully penetrated customer networks. The breach, tracked as CVE-2026-18577, prompted the release of a second mandatory hotfix, version 2026.3.1.10. While the company stated that a limited number of clients were impacted, specific figures regarding affected systems and post-breach activities remain undisclosed.
Key points
- N-able, a remote monitoring and management software vendor, confirmed that malicious actors exploited a zero-day flaw tracked as CVE-2026-18577 in its N-central platform.
- Attackers gained administrative access, utilized the built-in Take Control feature to reach managed client environments, and established persistence by registering Cloudflare Tunnel services.
- Security firm Huntress initially observed the malicious behavior in the wild, which N-able later verified through its own internal investigation.
- N-able stated that a limited number of customers experienced impacts, though the vendor declined to disclose exact numbers or the full scope of downstream system access.
- In response to the active exploitation, N-able released Hotfix 2, version 2026.3.1.10, and urged all on-premises N-central operators to install the update immediately.
IT management software provider N-able has officially confirmed that attackers exploiting a critical zero-day vulnerability in its N-central platform successfully breached downstream customer networks. The security flaw, designated as CVE-2026-18577, grants unauthenticated attackers administrative access to vulnerable remote monitoring and management servers.
According to N-able's Thursday disclosure, malicious actors leveraged this access to enter internal client environments using the platform's Take Control feature. To maintain persistent access despite potential server-side remediation, the attackers registered new Cloudflare Tunnel services—a technique previously documented in the wild by security firm Huntress. N-able verified that its own investigation uncovered identical attacker behavior across a limited number of affected organizations.
Despite confirming the downstream intrusions, N-able has not disclosed exact figures concerning the number of impacted customers, the volume of affected downstream systems, or the specific actions taken by the attackers once inside the networks. When questioned by reporters, the company did not provide detailed metrics, instead issuing a statement emphasizing ongoing threat monitoring and the proactive expansion of customer protections.
Alongside its updated findings, N-able deployed Hotfix 2, cataloged as version 2026.3.1.10. The vendor strongly urges all administrators running on-premises instances of N-central to apply the mandatory security patch immediately to mitigate ongoing risks associated with the exploit.
Sources
The WireByte editorial team synthesises technology news from multiple primary sources, verifies the facts, and links every source. Articles are produced with AI assistance and reviewed under our editorial policy.