hacker-news · Crawled Aug 8, 2026

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

10 IoCs
Read original article ↗

AI Summary

N-able has released Hotfix 2 for its N-central Remote Monitoring and Management (RMM) product to address ongoing exploitation of a critical authentication bypass vulnerability, CVE-2026-18577, which has been actively exploited in the wild. The vulnerability, impacting versions prior to 2026.3.1.7, allows attackers to achieve remote administrative access and perform account takeover. Once inside, threat actors have used the Take Control feature to access managed systems and establish persistence via Cloudflare Tunnel services, even after N-central access was revoked.

AI-extracted · verify before operational use

Indicators of Compromise 10 extracted

Type Value Detail
IP 173[.]249[.]252[.]176 Details →
IP 173[.]249[.]252[.]200 Details →
IP 185[.]156[.]46[.]150 Details →
IP 23[.]234[.]94[.]43 Details →
IP 37[.]153[.]90[.]88 Details →
IP 37[.]19[.]210[.]32 Details →
IP 68[.]235[.]46[.]214 Details →
IP 68[.]235[.]46[.]235 Details →
IP 87[.]249[.]138[.]34 Details →
IP 92[.]118[.]112[.]181 Details →