Critical N-able N-central Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding active exploitation of a critical authentication bypass vulnerability in N-able’s N-central platform. This flaw, identified as CVE-2026-18577, affects N-central servers running versions prior to 2026.3.1.7.

N-central is a remote monitoring and management (RMM) solution widely utilized by managed service providers (MSPs) to oversee client systems. Given its central role in managing numerous endpoints, a compromise of N-central could grant attackers extensive access across managed environments.

The vulnerability, CVE-2026-18577, is classified as an authentication bypass via an alternate path or channel, corresponding to CWE-288. N-able has indicated that this issue stems from an incomplete patch for a previously addressed flaw, CVE-2026-18556.

Exploitation Details

According to N-able, attackers have exploited this vulnerability to gain remote administrative access to vulnerable N-central servers. Once in control, the threat actors utilized the platform’s Take Control feature to access systems managed through N-central. They further established a new Cloudflare Tunnel service, providing a persistence mechanism that allowed continued access to the affected environment even after initial access to the N-central server was revoked.

N-able first detected increased licensing issues among on-premises N-central customers on July 31, 2026. By August 2, during their investigation, the company identified an additional exploitation method. In response, N-able released a hotfix for N-central 2026.3 and urged all customers to upgrade to version 2026.3.1.7 immediately.

Mitigation and Recommendations

On August 3, 2026, CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog, mandating that federal civilian executive branch agencies apply mitigations by August 6, 2026, under Binding Operational Directive 26-04. CISA also advised organizations to assess internet exposure, follow vendor instructions, and discontinue use of the product if mitigations are unavailable.

N-able reported that only a limited number of customers have been identified as affected, with support teams contacting those organizations directly. However, the company cautioned that its investigation is ongoing and that more indicators may emerge.

Administrators are advised to patch N-central systems without delay, enforce multi-factor authentication, audit privileged accounts, and monitor managed endpoints for unusual remote-control activity or persistence mechanisms. Additionally, organizations should review logs, account activity, remote access sessions, newly created services, and Cloudflare Tunnel configurations.

Given the critical nature of this vulnerability and its active exploitation, prompt action is essential to safeguard systems and prevent potential widespread compromise.