N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
N-able has confirmed that attackers exploiting a critical zero-day in its N-central remote management platform reached customer networks, not just the management servers themselves. The incident matters because N-central is used by managed service providers to administer many organisations’ systems, making it a potentially valuable route for attackers to move downstream into customer environments.
The flaw, CVE-2026-18577, allowed unauthenticated administrative access and was first detected on 31 July; N-able issued an initial hotfix on 2 August. Attackers used N-central’s Take Control feature to access managed systems and installed Cloudflare Tunnel services for persistence, with a “limited number” of customers affected. N-able has now issued mandatory Hotfix 2, version 2026.3.1.10, for on-premises customers, while hosted environments have already received the mitigations; US federal agencies were given three days to patch after CISA listed the vulnerability as actively exploited.
- Attackers used N-central to reach customer networks.
- A second mandatory hotfix is now available.
- N-able has not disclosed the scale of impact.