N-able is warning customers that a newly discovered authentication bypass vulnerability, tracked as CVE-2026-18577, is being actively exploited against both hosted and on-premises N-central servers. The flaw affects all versions of the remote monitoring and management (RMM) platform prior to 2026.3 and can grant attackers administrator access.
According to N-able and reporting from BleepingComputer, the vendor first disclosed active exploitation on August 1st and launched an investigation. That probe uncovered CVE-2026-18577 as an additional issue tied to an incomplete fix for an earlier vulnerability, CVE-2026-18576, described as an authentication bypass using an alternate path or channel that affected all N-central versions through 2026.1. Both flaws could be leveraged for administrative account takeover.
N-able released hotfix 2026.3.1.7 on Sunday to address the issue. Hosted deployments have already received the update automatically, but customers running on-premises instances must install the hotfix manually and are strongly urged to do so immediately.
Indicators of Compromise
N-able has not disclosed technical details about the vulnerability or the scope of exploitation, including how many customers may have been targeted or compromised. However, the company published indicators of compromise on its hotfix download page, including four specific IP addresses, a registered service named “Cloudflared,” and an “svchost.exe” file found in users’ Documents folders.
Security teams should note that Cloudflared, Cloudflare’s legitimate tunneling utility, is frequently abused by attackers to establish outbound tunnels that provide remote access to compromised systems without needing to open inbound firewall ports. Any of these indicators found in an environment should prompt customers to immediately contact N-able support and engage their internal security teams.
Why This Matters
N-central is widely used by managed service providers and corporate IT departments to manage large fleets of multi-OS systems and network devices. Compromise of these servers can allow attackers to pivot beyond N-able’s direct customer base into downstream client networks.
This is not the first time the platform has been targeted. Zero-day attacks against N-central last year prompted CISA to issue an urgent alert. RMM and MSP platforms remain high-value targets for threat actors, with previous incidents affecting Kaseya VSA, ConnectWise ScreenConnect, SimpleHelp, and SolarWinds Orion.
N-able says agent updates are not strictly required to mitigate CVE-2026-18577 but recommends applying them to receive the latest fixes and features. The company has advised customers to remain vigilant and monitor their environments closely, and has promised further updates as the investigation continues.
