Vulnerability in N-able N-central exploited to access managed endpoints

An authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a widely used remote monitoring and management (RMM) solution by managed service providers (MSPs), is being exploited by attackers to gain access to managed endpoints. The discovery was announced by N-able on August 2, 2026, following an unusual spike in licensing issues for on-premise customers.

The vulnerability, which affects all versions of N-central prior to 2026.3.1.7, was identified during the analysis of a previously addressed vulnerability (CVE-2026-18556), which had been resolved in version 2026.2. The corrective patch (2026.3 Hotfix 1) was automatically distributed to provider-hosted instances, while self-hosted customers must apply the fix manually.

Active exploitation and slow patching

N-able confirmed that attackers have breached installations of a "limited" number of customers, taken control of an administrator account, and abused the Take Control function to connect to managed endpoints. Once on these devices, attackers registered a new service for a CloudFlare tunnel, allowing persistence in the environment even after revoking access to the N-central server.

Huntress, a managed cybersecurity firm focusing on small and medium businesses and the MSPs serving them, confirmed that exploitation of CVE-2026-18577 is ongoing. According to Huntress, more than half (55.6%) of reachable cloud servers of partners and customers had not yet been updated at the time of the update's release. This is particularly concerning because the N-central server runs a custom distribution of AlmaLinux 9 and often lacks installed EDR software.

Relevance of vulnerabilities in RMM solutions

RMM tools are an ideal target for attackers who want to reach many organizations to lay the groundwork for follow-up attacks or penetrate deeper into a target organization. This is not the first time vulnerabilities in N-central have been exploited. In 2025, for example, other vulnerabilities in MSP-friendly RMM solutions were exploited.

Organizations with self-hosted N-central servers should update to the correct version and check the server for signs of administrator account takeover. They should also inspect endpoints managed via N-central, as that is where attackers have established persistence.

Recommendations for detection and mitigation

To detect if you have been affected, N-able advises examining the Documents folder on managed devices for a file called 'svchost.exe' and looking for a registered service named 'Cloudflared'. The company has also shared a list of IP addresses used by the attackers.

According to Huntress, the vulnerability allows attackers to gain the same level of control normally reserved for trusted network and engineering personnel. This enables them to perform operations such as sending new scripts and jobs to managed endpoints, deploying and executing dual-use tools like remote tunnels or discovery utilities via the N-able agent, and initiating remote control sessions on servers and workstations.

Attackers can also modify relevant security configurations—roles, accounts, and policies—to pave the way for follow-up activities. So far, observed activity related to these attacks has focused on establishing persistence on managed endpoints.

Considerations for managed endpoint security

Huntress advises potentially affected organizations to isolate N-central distributions; update and harden them; look for unusual logons, account modifications and permissions, new jobs and automations; and review recent Take Control sessions. Turning off N-central is a significant decision and should be based on risk, not panic.

For high-risk organizations, or where it is not possible to significantly reduce exposure, the safest choice might be to temporarily disable N-central until N-able's corrective patch can be applied. The goal is not to tell every N-able customer to turn off their server but to raise awareness about the risks.

Editorial Note and Disclaimer

Guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.