N-able Ships N-central Hotfix 2 as Attackers Persist Past the First Fix
N-able's first N-central hotfix didn't end the intrusion. Attackers reached the managed systems behind the RMM platform and kept a foothold even after the server was locked down, so N-able has now shipped Hotfix 2 — required even if you already patched Hotfix 1.
N-able's first N-central hotfix did not close the incident. In the intrusions the vendor is still investigating, attackers reached the managed systems sitting behind N-central and stayed on them — keeping a foothold even after access to the N-central server itself was cut off. That persistence, rather than a brand-new vulnerability, is why N-able has now shipped a second hotfix.
On August 6, 2026, N-able released N-central Hotfix 2, an added round of hardening for the remote monitoring and management (RMM) platform tied to CVE-2026-18577. The company is blunt that this is a separate release, not a repackaging of the first patch: Hotfix 2 supersedes Hotfix 1 and is required even for administrators who already applied the earlier fix.
N-able framed the release as a reaction to attacker behavior, not a single bug. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. It then drew a hard line under any assumption that the first patch settled the matter: "This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers." (The research brief behind this piece paraphrased that as "not a duplicate of our [earlier hotfix]"; the wording quoted here is N-able's live statement.)
Why a Second Hotfix, and Why Now
The short version of the back story: N-central carried an authentication-bypass flaw, tracked as CVE-2026-18577 (CVSS 8.2), that let a remote attacker take over an administrative account. We covered the flaw and the incomplete first fix when it landed, the vendor's confirmation that attackers reached customer networks, and the CISA KEV listing that put a federal patch clock on it. Those are the background; the new development is what happens after the first patch.
According to N-able, the intrusion started with unusual activity spotted in a customer environment on July 31, 2026, which led to the discovery of the then-zero-day. The flaw is an incomplete fix for an earlier bug, CVE-2026-18556, and both were flagged as actively exploited by the U.S. Cybersecurity and Infrastructure Security Agency. What matters for Hotfix 2 is that patching the server did not, on its own, evict the attacker from the systems N-central manages.
What "Persist" Means for the People Who Have to Clean It Up
The load-bearing fact in this update is that the compromise is not self-clearing. Reaching the managed systems and holding position past the first hotfix means an MSP could apply Hotfix 1, see the server report clean, and still have an intruder resident on downstream endpoints. N-able has since disclosed the shape of that foothold — attackers registered a new service to stand up an outbound tunnel, which kept access alive after the N-central server path was closed. We are describing that only as something to audit for, not as a method to reproduce.
N-able is candid about the limits of its own tooling here. It has published a detection recipe that checks managed Windows endpoints against known indicators of compromise, but it cautions: "A clean result should not be interpreted as a guarantee that your environment has not been impacted. Our investigation is ongoing and additional indicators may be identified over time." Read that as a standing instruction to keep looking rather than to close the ticket.
What Is Confirmed, and What Is Still Open
Confirmed by the vendor: this is Hotfix 2, it supersedes Hotfix 1, it is mandatory regardless of the earlier patch, and a "limited number of customers" were affected. N-able has expanded its published list of indicator IP addresses and released a detection template for managed Windows endpoints.
Still open, and worth flagging rather than papering over: N-able has not said whether Hotfix 2 fully closes the persistence path — its own "ongoing investigation" language suggests it is not treating the book as shut. The vendor has not named the compromised MSPs, has not given a downstream endpoint count, and there is no confirmation that CISA is revising its KEV entry to reflect the persistence behavior. The specific foothold mechanism has now been disclosed at a high level, but the fuller reconstruction is not something defenders need in order to act — and not something we will publish.
My Read
My read: the story here is not another CVE, it is that the fix and the eviction are two different jobs. An MSP that patched fast and moved on is exactly the shop most exposed right now, because the server can look healthy while the managed fleet behind it is not. Two hotfixes inside a single investigation, plus a vendor that keeps saying a clean scan is not a guarantee, is a signal to run the endpoint audit and the credential rotation as their own workstream — separate from "did we patch." If a third hotfix arrives, it will almost certainly be about hardening that same managed-systems boundary rather than a new front. Plan for the audit to outlast the patch.