A China-linked threat actor is believed to be exploiting a critical vulnerability affecting cybersecurity software from the company N-able.