N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
ID: 053d026f-ffe4-52ad-9963-f31f00f74376
STIX ID: report--053d026f-ffe4-52ad-9963-f31f00f74376
Feed Name: Help Net Security
Threat Score
**Active exploitation of N‑able N‑central zero-day (CVE-2026-18577):** N‑able released Hotfix 2 after detecting a bypass variant being actively exploited to compromise N‑central instances, with attackers using Take Control to access endpoints, establish CloudFlare tunnel persistence, create domain accounts, disable EDR, perform rapid lateral movement and deploy ransomware linked to Storm-1175; N‑able and researchers published IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
