N-able warns of N-central auth bypass flaw exploited in attacks

N-able’s N-central Servers Under Attack: Urgent Update Required to Patch Authentication Bypass Flaw

A severe security vulnerability affecting N-central servers has been actively exploited by hackers, prompting a swift response from the vendor. N-able, the company behind the Remote Monitoring and Management (RMM) platform, has released an emergency hotfix to address the issue, which affects all versions of N-central before 2026.3. The authentication bypass flaw, identified as CVE-2026-18577, allows threat actors to gain unauthorized access to N-central servers, potentially leading to administrative account takeover.

The vulnerability is particularly concerning because it affects both hosted and on-premises N-central deployments. This means that not only customers who use the cloud-based version of the platform are at risk but also those with on-premises installations. Compromising these servers can have far-reaching consequences, as threat actors may use them to extend their attack beyond N-able’s direct customers.

N-central is a popular RMM platform used by managed service providers (MSPs) and corporate IT departments to manage large clusters of multi-OS systems and network devices. The product has been targeted in the past, including last year when it was hit with zero-day attacks that prompted the US Cybersecurity and Infrastructure Security Agency (CISA) to issue an urgent alert.

The authentication bypass flaw is related to a previously patched vulnerability, CVE-2026-18576. While N-able has not provided technical details about the security issue or shared information on the number of customers targeted or compromised, the vendor has released indicators of compromise that can be found on the hotfix download page. These include specific IP addresses, a registered service named ‘Cloudflared,’ and ‘svchost.exe’ in the users’ documents folder.

If any of these indicators are detected, customers are advised to contact N-able support immediately and engage their own security team. It’s worth noting that attackers often abuse Cloudflared, a legitimate tunneling utility from Cloudflare, to create outbound tunnels that expose compromised machines or provide remote access without opening inbound firewall ports.

While agents do not require immediate updates to mitigate CVE-2026-18577, N-able strongly recommends updating them to get the latest fixes and features. The vendor has also emphasized the importance of remaining vigilant and monitoring environments closely.

In light of this incident, it’s essential for organizations that use N-central to prioritize patching their servers as soon as possible. This is not a trivial task; in fact, research suggests that security teams log only 14% of successful attacks, with the majority slipping through undetected. To mitigate such risks, regular security audits and penetration testing are crucial.

Ultimately, this incident serves as a stark reminder that cybersecurity threats can emerge from anywhere, even within trusted vendor ecosystems. It’s essential for organizations to remain proactive in their approach to security, staying one step ahead of attackers by continuously monitoring their environments and updating their defenses.


Source: Bleeping Computer — 2026-08-03