N-able Ships Second N-central Hotfix as Active Exploitation Reaches Managed Endpoints
N-able has issued a second round of hotfixes for its N-central Remote Monitoring and Management (RMM) platform, expanding on earlier patches as it continues investigating active exploitation of a recently disclosed vulnerability in the product. According to The Hacker News, N-able says it is "proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," and that this hotfix is not a duplicate of the prior fix — it addresses new attacker behavior observed since the initial disclosure. Notably, the report indicates attackers have reached managed endpoints downstream of compromised N-central instances and are attempting to persist there, not just on the RMM server itself.
Why It Matters
RMM platforms like N-central sit at a uniquely privileged point in the supply chain: a single compromised instance can provide an attacker with administrative reach into every endpoint the MSP or IT team manages. That an attacker apparently pivoted from N-central into downstream managed systems raises this beyond a single-product patching concern — it's a potential foothold for lateral movement across every organization that instance touches. MSPs, MSSPs, and internal IT teams running N-central are directly exposed, as are their downstream customers even if those customers have no direct relationship with N-able.
What Defenders Should Do Now
- Apply the latest N-central hotfix immediately and confirm patch level against N-able's advisory — do not assume the first round of fixes is sufficient, since N-able explicitly frames this as addressing evolved attacker techniques.
- Audit N-central server logs and agent-deployment/task-execution history for unexpected script pushes, new agent installs, or configuration changes around the disclosure window.
- On endpoints managed via N-central, hunt for unfamiliar persistence mechanisms introduced through the RMM agent's own capabilities — new scheduled tasks, services, or scripts deployed via N-central rather than local admin tooling.
- Review N-central admin accounts and API keys for signs of credential compromise, and rotate credentials tied to the platform out of caution.
- Treat any managed endpoint touched by a potentially compromised N-central instance as needing individual verification, not just the RMM server itself.
Developing Story
Details here are limited — no CVE identifier, technical root cause, or full list of affected versions has been confirmed in what's been reported so far, and N-able's investigation is described as ongoing. We'll update as more specifics emerge. Read the original report at The Hacker News.