Skip to content
theregister·

🚨N-able Zero-Day Exploit Hits N-central

Hackers Used a Zero-Day to Take Over MSPs' Systems

TL;DR

Attackers exploited a zero-day vulnerability in N-able's N-central platform, gaining unauthenticated admin access. The company released Hotfix 2 on August 2 to mitigate the issue.

N-able confirmed attackers leveraged an N-central zero-day vulnerability to gain unauthorized administrative access. Once inside, hackers used the Take Control feature and Cloudflare Tunnel service to maintain a foothold within customer environments. A mandatory update, Hotfix 2 (version 2026.3.1.10), was released on August 2 for all on-premises users. This incident highlights the critical nature of managed service providers' platforms as entry points into their customers’ systems.

N-able Zero-Day Exploit Hits N-central — theregister

Key Points

1

Attackers exploited an unpatched vulnerability in N-central before the company issued Hotfix 1 on Aug 2

2

Hotfix 2 (version 2026.3.1.10) supersedes earlier updates and adds additional security measures

3

N-able first detected suspicious activity via its Adlumin service on July 31, leading to the vulnerability disclosure

4

The company released a list of 10 IP addresses used in attacks and provided a Windows endpoint hunting template

5

CISA added the bug to its Known Exploited Vulnerabilities catalog by August 6 for US federal agencies

Why It Matters

Managed service providers using N-central should urgently apply Hotfix 2. This update is crucial as it mitigates an unauthenticated administrative access vulnerability that allowed attackers to compromise customer systems via the platform.

N-ableN-centralzero-day exploitmanaged service providerscloud security

Frequently Asked Questions

Why does this matter?

Managed service providers using N-central should urgently apply Hotfix 2. This update is crucial as it mitigates an unauthenticated administrative access vulnerability that allowed attackers to compromise customer systems via the platform.

What happened?

Attackers exploited a zero-day vulnerability in N-able's N-central platform, gaining unauthenticated admin access. The company released Hotfix 2 on August 2 to mitigate the issue.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,713 builders reading daily.