Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

N-able’s Remote Monitoring Platform Hit by Critical Patch Bypass Flaw, Attackers Gain Administrator Access

A critical patch bypass vulnerability in N-able’s popular remote monitoring and management (RMM) platform has been exploited by attackers to gain administrator access to customer environments. The flaw, tracked as CVE-2026-18577, was discovered by the vendor over the weekend and affects a limited number of customers who have not yet updated their systems.

For those unfamiliar with RMM platforms, they allow IT teams and managed service providers (MSPs) to remotely monitor and manage customer systems, deploy software and patches as needed, and access endpoints through features like “Take Control”. N-central is one such platform used by thousands of customers worldwide. Attackers exploited the vulnerability to gain administrator access, which can be catastrophic if left unchecked.

The exploitation was first detected on July 31, when N-able’s security teams noticed an unusual spike in licensing issues for its on-premises customers. Further investigation revealed that a previously addressed authentication bypass vulnerability (CVE-2026-18556) contained another vector that attackers could use to gain administrator access. This exploit allowed the attackers to leverage the “Take Control” feature and connect to systems within the N-central managed environment.

Once inside, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into the environment even after their access to the N-central server was revoked. N-able’s engineering team quickly developed and published a fix for the vulnerability (CVE-2026-18577), which has been assigned a CVSS score of 8.2.

While N-able estimates that only a limited number of customers have been impacted by this vulnerability, Huntress, a cybersecurity firm, reports seeing exploitation impacting one organization in its customer base and many environments where the N-central server had not yet been updated to the latest version (2026.3.1.7). Moreover, nearly all cloud-hosted servers have been patched as of now, but 13.6% of reachable servers remain unpatched, with the majority being self-hosted.

Experts warn that a compromised RMM platform can be used to “run scripts, push tools, and open remote sessions across every downstream endpoint it manages”, making it essential for affected customers to take immediate action. N-able recommends upgrading to version 2026.3.1.7 as soon as possible, while hosted customers receive the fix automatically.

In addition to patching, Huntress advises organizations to harden their N-central environment by scanning logins and accounts for suspicious activity, reviewing remote control activity, and assessing system configurations regularly. With the stakes so high, it’s crucial that IT teams and MSPs take proactive measures to secure their RMM platforms against potential threats.

Ultimately, this incident serves as a reminder of the importance of staying up-to-date with security patches and regularly monitoring system logs for signs of compromise. By taking these precautions, organizations can minimize the risk of falling victim to such attacks in the future.


Source: Dark Reading — 2026-08-03