European managed services provider N-able has confirmed that attackers exploited a critical zero-day vulnerability in its N-central software, gaining access to customer networks. The company released a second mandatory hotfix just days after the first as part of ongoing security measures to mitigate the threat. The flaw, CVE-2026-18577, allows an unauthenticated attacker administrative control over remote monitoring and management platforms. According to N-able's update on Thursday, attackers exploited vulnerable servers remotely before using the platform’s Take Control feature to connect to downstream systems managed by these servers.
Background
The vulnerability was first discovered when suspicious activity was detected in a customer environment via Adlumin Managed Detection and Response service on July 31. The flaw was publicly disclosed as CVE-2026-18577, prompting N-able to release its initial hotfix on August 2.
Market / Industry Impact
The incident highlights the critical nature of security updates for managed services providers (MSPs) operating in Europe and beyond. The rapid deployment of a second fix underscores the evolving threat landscape that companies must navigate. European cybersecurity regulations, such as those enforced by CISA within the US federal context, will likely influence similar directives across EU member states.
What to Watch
N-able has published 10 IP addresses used in attacks and released a service template for identifying indicators of compromise on Windows endpoints. However, customers are advised not to consider clean scans as conclusive evidence of security without further investigation. The company also warns that threat actors may continue evolving their techniques despite the latest hotfixes. N-able’s proactive stance indicates ongoing monitoring will be necessary moving forward.
Takeaway
MSPs and IT administrators must remain vigilant in applying critical updates to protect against emerging threats like CVE-2026-18577, particularly when managing large numbers of customer systems from centralized platforms.