N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
What happened
N-able confirmed attackers exploited a critical N-central zero-day (CVE-2026-18577) to gain administrative access and used the product's Take Control feature to reach downstream customer systems. The vendor released a second mandatory hotfix, published about ten IP addresses and a hunt template, and CISA added the bug to its Known Exploited Vulnerabilities list with an accelerated fix expectation. Buyers should verify which suppliers run affected RMM instances and whether downstream systems were reached in their supplier chains
Why the category manager should care
Treat N-central and similar RMMs as mission-critical supplier controls that must be patched, monitored, and contractually covered because vendor compromise allowed downstream reach
Key facts
- Exploit of N-central CVE-2026-18577
- Vendor issued Hotfix 2 and published ~10 IP addresses and a hunt template
- CISA added the bug to its Known Exploited Vulnerabilities list