N-ABLE has patched a vulnerability (CVE-2026-18577) that was actively exploited against its N-central remote monitoring product, leading to potential unauthorized access to user accounts in versions prior to 2026.3.1.7. The vulnerability is not a new zero-day but a newly exploited method related to a previously patched issue (CVE-2026-18556), with exploitation confirmed beginning in late July.
Attackers could gain administrative access, leverage remote control features, and execute malicious actions on managed systems. N-able identified a limited customer impact, but many organizations had not yet implemented patches as of August 3, raising significant security concerns.