What happened
N-able released a second security hotfix for N-central on August 10, closing a hole that attackers were still using after the first fix. N-central is a remote monitoring and management platform used heavily by managed service providers — the outside IT companies that many small businesses hire to run their systems. The exploited flaw, CVE-2026-18577, is an authentication bypass that works around the patch N-able issued for an earlier vulnerability. Exploitation was first detected in a customer environment on July 31, N-able confirmed attacks on August 1, and Hotfix 1 followed in early August. When attackers found a variation that slipped past it, the company shipped Hotfix 2, version 2026.3.1.10, and said it is required even for servers that already applied the first fix. Security firms watching the campaign report attackers creating domain accounts, deploying tools to evade endpoint defenses, and going after domain controllers. Microsoft attributes the activity to Storm-1175, a financially motivated group known for fast-moving ransomware operations.
Why it matters for your business
This is a supply-chain problem in the most practical sense: the software your IT provider uses to manage your computers is the same software attackers are exploiting. A compromised RMM platform gives an intruder the same reach your MSP has — every managed workstation and server. N-able also cautioned that patching closes the door but does not remove anyone who already walked through it.
What to do about it
- If you use an MSP, ask directly whether they run N-central and whether Hotfix 2 (2026.3.1.10) is applied
- Ask whether they have reviewed accounts, access privileges, and activity for signs of intrusion, not just applied the patch
- If you self-host N-central, patch now and work through the published indicators of compromise
- Keep offline backups current in case ransomware follows
