CYBERSECURITYTRACKER
TRACKING7,631 stories in this site build1,635 vulnerability news stories in this site build
Permanent story citation

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4148

As cited

Copy frozen at (site build).

vulnerabilities

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able released a second security hotfix for N-central, its remote monitoring and management (RMM) solution, to address ongoing exploitation of CVE-2026-18577. The company stated that Hotfix 2 is required even for customers who applied the initial patch, as it includes additional hardening measures. N-able also disclosed new indicators of compromise observed in active attacks.

Why it matters: MSPs and their customers using N-central face active exploitation of this vulnerability; deploying Hotfix 2 immediately is critical to prevent unauthorized access to managed systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

N-able released a second security hotfix for N-central, its remote monitoring and management (RMM) solution, to address ongoing exploitation of CVE-2026-18577. The company stated that Hotfix 2 is required even for customers who applied the initial patch, as it includes additional hardening measures. N-able also disclosed new indicators of compromise observed in active attacks.

Why it matters: MSPs and their customers using N-central face active exploitation of this vulnerability; deploying Hotfix 2 immediately is critical to prevent unauthorized access to managed systems.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary