Summary
- N-able says on-premises customers must install Hotfix 2 even if they already applied the first emergency fix.
- Attackers used N-central's Take Control capability to connect to systems inside managed environments.
- The incident shows how compromise of remote-management infrastructure can extend beyond the original control plane.
N-able has issued a second mandatory hotfix for its N-central remote monitoring and management platform as the company responds to changing attacker techniques in an incident that has already reached systems inside managed customer environments.
N-able released build 2026.3.1.10 on 6 August and told organisations running N-central on premises that they must install it even if they had already deployed the first emergency hotfix. Hosted N-central environments have been mitigated by the company and require no customer action.
The update follows detection of unusual activity on 31 July by N-able’s Adlumin managed detection and response service. The investigation identified active exploitation of a previously unknown N-central vulnerability and led to the first emergency release, build 2026.3.1.7.
N-able now says Hotfix 2 supersedes that release and adds further hardening as threat actors evolve their techniques.
The company’s investigation has also established that attackers moved beyond the N-central server. After obtaining administrative access, they used the platform’s legitimate Take Control functionality to connect to systems inside managed environments.
On those endpoints, attackers registered a Cloudflare tunnel service, creating an access path that could persist after their route through N-central had been revoked. The finding changes the scope of incident response from repairing a vulnerable management server to establishing what occurred on systems that the compromised platform was authorised to control.
The earlier N-central investigation had already shown how privileged remote-management tooling can transfer exposure downstream. The second hotfix makes clear that the vendor’s mitigation work is continuing rather than complete.
Remote monitoring and management platforms occupy a sensitive position because their legitimate purpose is to centralise administration across many machines. Managed service providers use them to deploy software, troubleshoot systems, execute remote sessions, and administer customer estates efficiently.
Those same privileges magnify the consequence of compromise. An attacker controlling the management plane does not necessarily need to deploy a novel remote-access tool if the legitimate platform already provides the required functionality. Activity can also resemble normal administrative behaviour until the context around the session is understood.
The Cloudflare tunnel finding illustrates a further recovery problem. Once an attacker establishes an independent persistence mechanism on a managed endpoint, patching the original N-central server or revoking its administrative session does not automatically remove that foothold.
That makes containment dependent on distinguishing between the original access path and everything performed after it. Credentials, services, scheduled tasks, remote-access components, and other changes on managed systems may need separate examination even where the central server has already been updated.
The incident also sits inside a broader third-party resilience problem. Organisations delegate privileged access to managed service providers because centralised administration reduces cost and complexity. The model depends on the management infrastructure remaining trustworthy, and a failure at that layer can cross organisational boundaries quickly.
N-able has published indicators and detection material associated with the activity. Those indicators describe evidence found so far and should not be treated as a complete definition of possible compromise while the investigation remains active.
The precise number of affected customers and full extent of attacker activity have not been publicly established. The confirmed sequence is enough to increase the response burden: attackers exploited N-central, used its legitimate remote-control capability to reach managed systems, established separate persistence on some endpoints, and N-able has now required a second hotfix for on-premises installations.



