Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

Cyber Attackers Exploit Patch Bypass Flaw on RMM Servers, Gain Administrator Access

A severe cybersecurity threat has emerged over the weekend as attackers exploited a patch bypass flaw in N-able’s Remote Monitoring and Management (RMM) platform, known as N-central. The vulnerability, tracked as CVE-2026-18577, allows malicious actors to gain administrator access to customer environments, highlighting the importance of timely software updates and vigilant monitoring.

N-able, a leading provider of security and IT management tools for managed service providers (MSPs) and internal IT teams, disclosed the active exploitation through its status update page and an Aug. 2 blog post. The company’s engineers discovered that a previously addressed vulnerability, authentication bypass CVE-2026-18556, contained another vector for attackers to exploit, leading to unauthorized access to vulnerable N-central servers.

According to Huntress, a cybersecurity firm that has been tracking the attack, the threat actors leveraged the “Take Control” feature in N-central to remotely access customer endpoints. Once on these devices, they registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N-central server was revoked. This level of access allows attackers to run scripts, push tools, and open remote sessions across every downstream endpoint managed by the compromised server.

The impact of this vulnerability is significant, with nearly 13.6% of reachable servers remaining unpatched as of now. Huntress has seen exploitation impacting one organization in its customer base so far, but notes that many environments have not yet been updated to the latest version of N-central, which includes a fix for the vulnerability.

The stakes are high for organizations that have not patched their N-central instances. A compromised server can be used as a launchpad for further attacks, allowing malicious actors to gain access to sensitive data and systems. Huntress senior principal security researcher John Hammond notes that in the intrusions they’ve analyzed, the attacker uses N-central access to pivot into high-value servers, usually domain controllers, and immediately pulls a process list to understand what’s running and decide on next steps.

To mitigate this risk, N-able recommends customers not running the most recent version of N-central to upgrade to version 2026.3.1.7. Hosted customers receive the fix automatically, while on-premises customers must apply it themselves. Huntress also advises organizations to harden their N-central environment by scanning logins, accounts and configurations for changes that do not match normal operational patterns, reviewing remote control activity, and assessing the potential blast radius of a compromised server.

In conclusion, this attack serves as a stark reminder of the importance of timely software updates and vigilant monitoring in preventing cyber threats. Organizations that have not patched their N-central instances should take immediate action to upgrade and lock down their environments to prevent unauthorized access and potential data breaches.


Source: Dark Reading — 2026-08-03