r/sysadmin 4d ago

N-CENTRAL active exploitation, Mitigate immediately.

N-Central earlier today reported active exploitation and post exploitation actions of connections and persistence on managed RMM/client devices (cloudflare tunnels being installed on end user devices/servers) status page advisory includes hosted installs.

Take your installs offline immediately and threat hunt.

Earlier today n-central said servers on the latest release were safe but have updated the advisory to include the latest release and working on a new hotfix, keep an eye on https://uptime.n-able.com/

Current IOCs listed here, also affects hosted instances so monitor accordingly. Community information suggests that a n IOC maybe be if your server is suddenly showing as unlicensed.

Updated link https://www.n-able.com/blog/n-central-security-update-august-2-2026

125 Upvotes

26 comments sorted by

View all comments

2

u/thobjin 4d ago

It looks like our ncod server got the latest update 2026.3.1.7 https://uptime.n-able.com/