started · updated
N-able releases urgent Hotfix 2026.3.1.10 to close critical N‑central admin flaw
N-able has issued a mandatory Hotfix 2026.3.1.10 for its remote‑monitoring platform N‑central after confirming active exploitation of a zero‑day vulnerability (CVE‑2026‑18577) that scores 8.2 on the CVSS scale. The flaw allows attackers to bypass authentication and obtain administrative control of N‑central servers, enabling them to use the “Take Control” feature to access managed client systems and install a Cloudflare Tunnel for persistent access. The company detected unusual activity on a client environment on 31 July 2026, leading to the discovery of the exploit, which had been flagged by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) as actively exploited. N‑central versions prior to 2026.3.1.7 are affected; the new hotfix replaces earlier patches that did not fully remediate the issue. A limited number of customers, including on‑premise installations, have been impacted, and N‑able urges immediate update to the latest version.
The release includes expanded indicators of compromise and guidance for organizations to detect and mitigate the threat.
Entities
CVE-2026-18577 · Cloudflare · Cybersecurity and Infrastructure Security Agency · N-able · N-central