N-able has disclosed that attackers exploited an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) platform to seize administrative control of affected servers. The company said the flaw allowed intruders to reach downstream customer systems managed through compromised N-central instances.

The vulnerability, tracked as CVE-2026-18577, affects all N-central builds prior to version 2026.3.1.7. According to N-able, an earlier attempt to patch the issue proved incomplete, leaving a window in which attackers could still bypass authentication and obtain remote administrative access even after the initial fix was applied.

N-able shipped build 2026.3.1.7 on August 2 as the first version confirmed to fully address the vulnerability. The company is urging customers to update immediately rather than relying on any previously released interim patch.

Why This Matters

N-central is widely used by managed service providers (MSPs) to remotely monitor and administer client endpoints and infrastructure, making it a high-value target. An authentication bypass in this kind of platform gives attackers a direct path from a single compromised server into potentially dozens or hundreds of downstream customer networks, mirroring the supply chain risk profile seen in past RMM software incidents.

The fact that N-able’s first remediation attempt failed to fully close the gap underscores the difficulty of patching authentication logic flaws in complex management platforms, and it raises the stakes for administrators who may have believed they were already protected.

Recommended Actions

  • Upgrade all N-central instances to build 2026.3.1.7 or later immediately.
  • Do not assume any prior interim patch fully remediates CVE-2026-18577.
  • Review N-central server logs and administrative account activity for signs of unauthorized access predating the update.
  • Audit downstream customer systems managed through N-central for indicators of lateral movement or unauthorized configuration changes.
  • Rotate credentials and API keys associated with N-central administrative accounts as a precaution.

N-able has not detailed the scope of confirmed customer impact. Organizations running N-central should treat this as an active exploitation scenario and prioritize the update alongside a review of managed endpoints for compromise.