Vulnerabilities

N‑able Patches Vulnerability Exploited to Hack N-central Servers

The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.

N-Able N-central vulnerability exploited

N‑able has released patches for a vulnerability that has been exploited in the wild against users of its N-central remote monitoring and management (RMM) product.

The vulnerability, tracked as CVE-2026-18577, has been described as an authentication bypass issue that can be exploited to take over accounts in N-central versions prior to 2026.3.1.7. Both on-premises and cloud-hosted deployments are affected.

N-central is widely used by MSPs to monitor, patch, and remotely access customer servers and endpoints.

CVE-2026-18577 is not a new zero-day. Instead, N‑able has described it as a new method to exploit a previously patched vulnerability tracked as CVE-2026-18556.

It appears threat actors bypassed the patch for CVE-2026-18556 and started exploiting it in late July. The vendor initially saw an increase in licensing issues on July 31 and confirmed exploitation of CVE-2026-18577 on August 2.

Exploitation of the vulnerability has allowed attackers to gain admin access to the hacked N-central servers.

Advertisement. Scroll to continue reading.

“Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment. Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked,” N-able said in its incident notice.

N-able said a “limited number of customers have been impacted,” but cybersecurity firm Huntress, which has also confirmed seeing attacks exploiting CVE-2026-18577, said many organizations had yet to patch their installations as of August 3.

“From an MSP perspective, exploitation of this flaw can grant an attacker full administrative access to an N-central console — the same level of control normally reserved for trusted NOC and engineering staff,” Huntress warned.

It added, “Once inside the console, a threat actor can: push new scripts and jobs to many or all managed endpoints; deploy and run dual‑use tools (for example, remote tunnels or discovery utilities) via the N-able agent; initiate remote‑control sessions into servers and workstations, including domain controllers and other critical systems; and modify security‑relevant configuration such as roles, accounts, and policies to pave the way for follow‑on activity.”

Indicators of compromise (IoCs) have been made available by both N-able and Huntress.

News of the exploitation of CVE-2026-18577 comes almost exactly one year after organizations were warned about the exploitation of the N-central vulnerabilities CVE-2025-8875 and CVE-2025-8876.

Related: Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks

Related: Ruby on Rails Patches Critical Vulnerability

Related: Critical Flaw Allowed to Azure Cosmos DB Pwnage

Related Content

Vulnerabilities

CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

Artificial Intelligence

Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

Email Security

Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication.

Vulnerabilities

The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication.

Vulnerabilities

Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code.

Vulnerabilities

The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.

Vulnerabilities

The browser update resolves several critical-severity memory safety and memory corruption flaws.

Vulnerabilities

Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version