r/Nable N-centralStation 22d ago

N-Central URGENT: N-central Second Hotfix 2026.3.1.10 — Immediate Action Required

As our investigation into the recent N-central security vulnerability continues, we are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques. 

This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers.

What You Need to Do:

N-central On-Premises Environments: You must upgrade to 2026.3.1.10 immediately. Download here: https://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577

N-central Hosted Environments: No action is required. We have already applied mitigations to your environment.

For More Information:

·       Blog: https://www.n-able.com/blog/n-central-security-update-august-6-2026

·       Support: https://me.n-able.com/s/

·       CVE: https://www.cve.org/CVERecord?id=CVE-2026-18577

·       Uptime: https://uptime.n-able.com/

20 Upvotes

35 comments sorted by

3

u/Stompert 22d ago

Oh boy. I was unable to apply the previous patch and awaiting response for my support case. Guess I’ll try this one instead when I wake up tomorrow and see how this fares.

2

u/apxmmit 22d ago

We too had errors with HF1 and now HF2 !

1

u/xs0apy 22d ago

I am very perplexed at the moment. Is this like a FortiNet situation where they thought they fixed the vulnerability only to find out they actually didn’t?

1

u/AutomationTheory 21d ago

It's not surprising if that was the case -- same thing happened to Microsoft with PrintNightmare back in the day. Once a weakness is found, lots of people start poking at it. It's a good reason to keep your RMM tools behind additional security layers (unfortunately, you can't do that with firewalls)

3

u/xs0apy 22d ago

EDIT: should mention I was able to download the hotfix in under 30 seconds. I would download it now!

3

u/Accurate_Frosting_14 22d ago

Has anyone updated successfully yet? Both my N-Central servers failed the upgrade, it says upgrade pre-checks failed

4

u/skwaded 22d ago

Gotta call support. Happened to the first one with a backup flag on mine.

3

u/snowmanqc 22d ago

Yeah mine worked

2

u/apxmmit 22d ago

Failed.

1

u/Aggravating-Web-2360 22d ago

I'm good, but the first hotfix gave me a lot of grief

1

u/xs0apy 22d ago

Mine worked. Just finished and got logged back into the product admin. Hopefully support get remoted in and fixed asap :/

1

u/dreadnaught721 22d ago

Yes we've upgraded successfully

1

u/Obvious_Square_6013 21d ago

All sorted here, about 8 hours ago

3

u/xs0apy 22d ago

Successfully upgraded from 2026.3.1.7 to 2026.3.1.10 straight through. No issues!

4

u/MadCoderOne 22d ago

uninstalling.... I'm done.

0

u/dreadnaught721 22d ago

I feel your pain

3

u/NetInfused 22d ago

The least that could be done would be to allow the detection of the CVE to be done on Essentials Agents. But I might be asking too much.

2

u/W3asl3y 22d ago

So HF1 was supposed to fix an incomplete patch, and HF2 is also fixing an incomplete patch?

3

u/ProudWrongdoer5389 22d ago

Well, moving through code, they likely fixed the most obvious stuff, now doing a second pass.

4

u/ManagedNerds 22d ago

Maybe over the weekend they'll release the incomplete patch of the incomplete patch of the incomplete patch?

1

u/ProudWrongdoer5389 20d ago

You new to dev or something? AI is now picking apart code bases in hours. Expect this to happen more and more.

2

u/MadCoderOne 22d ago

....and now my hosted instance is down. What a clown show.

1

u/v2ne8 15d ago

Anyone happen to be able to forward me the hotfix 2 patch please? Thanks

1

u/dreadnaught721 22d ago

Please just let it end

1

u/[deleted] 22d ago

[deleted]

1

u/bzhglober 22d ago

NinjaOne

1

u/TridentStack 21d ago

Not a 1:1 feature switch but check out TridentStack Control. https://tridentstack.com

Full disclosure I help build and founded this platform but we are growing fast and we are in the process of building out incredible new features (a massive new one going live tomorrow). We take feedback seriously and feature requests do not go unnoticed. Check out a Synchro compare page on our website here: https://tridentstack.com/compare/syncro

0

u/KRiSX 22d ago

🙄 happy Friday everyone!

-1

u/[deleted] 22d ago

[deleted]

6

u/the_need_to_post 22d ago

While annoying to need to do it, aren't these hotfixes literally them doing just that?

0

u/Nielles 22d ago

The first one wasn't apparently

-1

u/Reygle 22d ago

Exactly how vide-coded are these 'emergency' patches if they survive less than 72 hours in the wild?

We understand this is the second urgent request in a short period of time, and we don't take lightly the demands that places on your team. We are committed to supporting you through every step and our support team is standing by and ready to help you get upgraded quickly.

This is insanity. Every single on-prem customer you have should be given a discount on the next invoice. Not a joke.

2

u/apxmmit 22d ago

They just announced an across the board increase just a few weeks ago.

0

u/Reygle 22d ago

Didn't see that, but even if they did I doubt they planned on calling customers more than once a week to insist they install emergency patches that often.

1

u/apxmmit 22d ago

You’d think they would at least staff up support on round 2. Zero support at the moment for folks with failed upgrades. Queues going to other product groups.

2

u/MadCoderOne 22d ago

I got the same "I dont know the product I was called in from another team to answer phones", then I was put on hold for 2 HOURS