Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026

    Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says
    • Reptiles, gold and money: How Australia is cracking down on wildlife trafficking
    • Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott
    • Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales
    • UK to fight Russian disinformation and push new global AI standards, Burnham says
    • Data centres: Developers hope fibre optics will cut power use
    • ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
    • $161 Million in Decade-Old Bitcoin Has Moved in Just Two Weeks
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 8, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 08, 2026Vulnerability / Enterprise Security

    N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.

    “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said.

    “This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.”

    The disclosure comes as N-able acknowledged that it detected unusual activity within a customer’s environment on July 31, 2026, leading to the discovery of unknown threat actors exploiting a then-zero-day flaw in the N‑central server (CVE-2026-18577, CVSS score: 8.2). It impacts all versions prior to 2026.3.1.7.

    It’s worth noting that CVE-2026-18577 relates to an incomplete fix for CVE-2026-18556 (CVSS score: 8.2). Both vulnerabilities, which allow authentication bypass and account takeover in susceptible versions, have been flagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

    Cybersecurity

    In the attacks observed by N-able, the vulnerability allowed the attackers to obtain administrative access remotely and then leverage the Take Control feature to connect to systems within the N‑central managed environment. Upon gaining access to those devices, the threat actors registered a new service for a Cloudflare Tunnel, enabling persistence even after access to the N‑central server was revoked.

    N-able has confirmed that a limited number of customers have been affected by the exploitation activity. Customers running an on-premise version are advised to update their instances to 026.3.1.10 immediately. The company has also shared an expanded set of IP addresses as indicators of compromise (IoCs) –

    • 173.249.252[.]176
    • 173.249.252[.]200
    • 185.156.46[.]150
    • 23.234.94[.]43
    • 37.153.90[.]88
    • 37.19.210[.]32
    • 68.235.46[.]214
    • 68.235.46[.]235
    • 87.249.138[.]34
    • 92.118.112[.]181

    In addition, N-able has released a custom service template that offers an automated way to check for known IoCs against Windows device endpoints in N‑central.

    “A clean result should not be interpreted as a guarantee that your environment has not been impacted,” it said. “Our investigation is ongoing and additional indicators may be identified over time. We strongly recommend this be used as one layer of your assessment, alongside a thorough review of your environment, logs, and account activity.”

    Attackers Hotfix issues managed Nable Ncentral persist reach Systems
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    Sweden fines Miljödata $183,000 over breach affecting 2.2 million

    Rogue external MFA providers can steal passwords during logins

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026

    Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott

    September 23, 2026

    Jesse Baird ‘petrified’ of Beau Lamarre-Condon and kept repeating ‘he has a gun’, court hears | New South Wales

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Democrats ‘chose visceral hatred for’ Donald Trump over crypto Clarity Act, Lummis says

    September 23, 2026

    Reptiles, gold and money: How Australia is cracking down on wildlife trafficking

    September 23, 2026

    Trump’s UNGA Speech: Threats to ‘Annihilate’ Iran, Calls for ICC Boycott

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.