N-able has released Hotfix 2 for its N-central remote monitoring and management platform after its investigation into an actively exploited authentication flaw confirmed that attackers reached managed endpoints, used the platform’s Take Control feature to connect to customer systems, and registered a Cloudflare Tunnel service to keep access alive. The vendor said Hotfix 2 is required even for customers that already applied the earlier update.
CVE-2026-18577 and the Incomplete Fix Behind a Second Hotfix
The update targets CVE-2026-18577, a CVSS 8.2 authentication bypass described by N-able as an incomplete fix for CVE-2026-18556, which also carries a CVSS 8.2 rating. CISA has flagged both vulnerabilities as actively exploited. Together they allow authentication bypass and account takeover on N-central servers, which the vendor said affects all versions prior to 2026.3.1.7.
Take Control Sessions Carried Attackers From the Server to Managed Systems
N-able’s account of the observed intrusions shows the attacker path extending well past the management console. Threat actors obtained remote administrative access to the N-central server and then used the platform’s Take Control feature to connect out to managed systems, according to the vendor’s disclosure. That progression turns a software flaw into hands-on access across a customer’s fleet.
Cloudflare Tunnel Registration for Persistence After Access Is Revoked
After reaching the devices, the attackers registered a Cloudflare Tunnel service. The move matters because it preserves access even after victim-side control reboots or the attacker loses the N-central session. N-able confirmed that a limited number of customers were affected and said its investigation remains ongoing.
The Expanded IoC List and the Vendor Detection Template
N-able published an expanded indicator list of ten IP addresses tied to the campaign, including 173.249.252.176, 173.249.252.200, 185.156.46.150, 23.234.94.43, 37.153.90.88, 37.19.210.32, 68.235.46.214, 68.235.46.235, 87.249.138.34, and 92.118.112.181. The vendor also released a custom service template designed to check Windows endpoints for the known indicators.
The Limits of the Template and the Need for Endpoint-Level Sweeps
N-able warned that a clean result from the detection template is not a guarantee that an environment was untouched. For managed service providers, that caveat effectively requires treating every managed endpoint behind a compromised N-central instance as a candidate for review, not for a single-pass scan.
Why RMM Server Compromise Is Measured at the Managed Endpoint Scale
The incident illustrates why a monitoring platform is such an attractive target: one authenticated bypass on the console translates into reach across every environment managed through it. Positioned as the trust anchor of the MSP relationship, N-central access gives an attacker a route to managed systems that would otherwise require a separate intrusion per customer.
Applying 026.3.1.10 and Treating Hotfix 1 as Insufficient
N-able directed on-premise customers to update to N-central 026.3.1.10 immediately and to treat Hotfix 2 as superseding the first patch, stating that Hotfix 2 is required even if the earlier hotfix was already applied. The agency advisory context reinforces the urgency: both underlying CVEs are on CISA’s actively exploited list.
Auditing Take Control Usage and Cloudflare Tunnel Service Registrations
The vendor’s response guidance points administrators to Take Control usage logs and to any Cloudflare Tunnel service registrations that appear on managed hosts. Those two artifacts are the concrete evidence trail an investigator would use to reconstruct where the attacker traveled inside a customer network.
Cloudflare Tunnel Footholds and the Case for RMM Console Hardening
Security practitioners have long flagged RMM platforms as prime initial-access or persistence infrastructure, and this incident adds Cloudflare Tunnel tunneling to the palette of techniques seen in such environments. The combination of an authentication bypass, remote-control abuse, and a tunnel-based foothold reinforces the argument that RMM consoles merit the same segmentation, auditing, and multi-factor hardening given to domain controllers, while the endpoint layer needs its own detection for outbound tunnel processes rather than assuming the management plane can be trusted to report its own compromise honestly.
