N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
CVE Tools coverage
N-able has issued a second security hotfix, version 2026.3.1.10, for its N-central Remote Monitoring and Management platform to address ongoing exploitation of CVE-2026-18577. This update supersedes the earlier Hotfix 1 (version 2026.3.1.7) and introduces additional hardening measures against a threat actor who successfully bypassed previous patches. Attackers are using the vulnerability to gain unauthorized access to managed endpoints, establish persistence via CloudFlare tunnels, and disable security software.