N-able shipped Hotfix 2, build 2026.3.1.10, for N-central on 6 August, adding hardening after watching attacker techniques change 1. N-central is remote monitoring and management software, known in the trade as RMM: the console a managed service provider uses to reach every customer endpoint it looks after. NHS England had alerted UK health organisations on 3 August, citing N-able, that attackers were exploiting CVE-2026-18577 to take over administrative accounts and obtain full administrative access to a server 2.
That flaw is an incomplete fix for CVE-2026-18556, the earlier bug it was issued to close, and both carry a score of 8.2 under version 4 of the Common Vulnerability Scoring System 3. Huntress, a US security firm that watches managed endpoints for its customers, saw attackers use N-central's Take Control feature, the built-in remote-control tool an engineer uses to take over a desktop, to reach the machines the console administers, then run tunnels through Cloudflare's tunnelling service to keep their access 4. Cloudflare's product is being used as designed by people who should not have it, which is a different thing from Cloudflare being breached.
Australia's ACSC, the Australian Signals Directorate's Australian Cyber Security Centre, reported targeting inside Australia on 19 August and said it had no information pointing to any particular sector 5. Two of the three public warnings on this product therefore came from national bodies outside the United States, and both arrived before the vendor's second fix had a fortnight behind it.
Management consoles have been the recurring shape in the federal exploited-vulnerability record all summer, with wide-area network, firewall and management-plane products filling the catalogue in a single ten-day stretch at the end of July . An RMM platform cannot be patched quietly. Taking the console down interrupts monitoring for every customer estate attached to it at once, which is why the date on a second hotfix matters more than the fact of one.
