hacker-news · Crawled Aug 8, 2026
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
10 IoCs
Read original article ↗
AI Summary
N-able has released Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product to address ongoing exploitation of a critical authentication bypass vulnerability, CVE-2026-18577, which has been actively exploited in the wild. The vulnerability, impacting versions prior to 2026.3.1.7, allows attackers to achieve remote administrative access and perform account takeover. Once inside, threat actors have used the Take Control feature to access managed systems and establish persistence via Cloudflare Tunnel services, even after N-central access was revoked.
AI-extracted · verify before operational use
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 173[.]249[.]252[.]176 | Details → |
| IP | 173[.]249[.]252[.]200 | Details → |
| IP | 185[.]156[.]46[.]150 | Details → |
| IP | 23[.]234[.]94[.]43 | Details → |
| IP | 37[.]153[.]90[.]88 | Details → |
| IP | 37[.]19[.]210[.]32 | Details → |
| IP | 68[.]235[.]46[.]214 | Details → |
| IP | 68[.]235[.]46[.]235 | Details → |
| IP | 87[.]249[.]138[.]34 | Details → |
| IP | 92[.]118[.]112[.]181 | Details → |