Threat Intelligence

N-able Rushes Second Hotfix as Hackers Continue Targeting N-central RMM Tool

The Hacker News · 8 Aug 2026
Key Takeaway If your business relies on an outsourced IT provider using N-central or similar RMM software, confirm with them immediately that the latest hotfix has been applied and that systems are being checked for signs of unauthorised access.

N-able has released another round of hotfixes for its N-central platform, a widely used Remote Monitoring and Management (RMM) tool for IT service providers, as part of its ongoing response to active exploitation of a previously disclosed security flaw. The company said the update is not simply a repeat of earlier fixes but a proactive expansion of protections based on continued monitoring of attacker behaviour.

According to N-able, threat actors have been evolving their techniques, managing to reach managed systems through the vulnerability and establish persistence — meaning they can maintain access even after initial detection or remediation attempts. This makes the issue particularly concerning for managed service providers (MSPs) and their small business clients, since RMM tools typically have deep, trusted access across many customer networks at once.

Because RMM platforms are a high-value target for attackers looking to compromise multiple downstream businesses through a single provider, any vulnerability in these tools carries outsized risk. N-able has urged customers to apply the latest hotfix promptly and continue monitoring for signs of compromise.

RMM Security N-able Patch Management MSP Risk Vulnerability Exploitation

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.