A critical zero-day vulnerability, designated as CVE-2026-18577, in N-able's N-central platform has been exploited by attackers, resulting in unauthorized access to customer networks. The vulnerability allows unauthenticated attackers to gain administrative access to the remote monitoring and management platform, which was then used to connect to internal systems using the Take Control feature. N-able has released a second mandatory hotfix to address the issue, following an initial fix, in an effort to mitigate the damage. The exploit has significant implications, as it expands the active attack surface, making it essential for organizations to prioritize their response based on exposure and evidence of exploitation1. This incident highlights the importance of prompt patching and vigilance in protecting against potential attacks, particularly for those with vulnerable N-central servers.