N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
What happened
N-able has released a second security hotfix for its N-central remote monitoring and management solution to address ongoing exploitation of CVE-2026-18577. This update supersedes the previous hotfix with additional hardening measures required to protect managed service providers and their customers.
Why it ranks #1
This is a material update to a previously reported incident, now escalating because the first patch was insufficient and active exploitation persists against enterprise management infrastructure.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Apply N-central Hotfix 2 immediately, even if Hotfix 1 was previously installed.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed