Skip Navigation

August 4, 2026 |

Active exploitation of N-able N-central authentication bypass flaw

Loading table of contents...

At a glance:

  • N-able has disclosed and patched an authentication bypass vulnerability in its N-central Remote Monitoring and Management (RMM) platform that was actively exploited before a fix became available.

  • The flaw allows a remote threat actor to gain administrative access to vulnerable N-central servers without valid credentials, enabling access to managed endpoints through the platform's built-in administration features.

  • Observed intrusions included access to managed systems, deployment of Cloudflare Tunnel services for persistence, and activity targeting high-value assets such as domain controllers.

Threat summary

On August 3, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577, an authentication bypass vulnerability affecting N-able N-central, to its Known Exploited Vulnerabilities (KEV) catalog after confirming active exploitation.

N-able N-central is a remote monitoring and management (RMM) platform used primarily by managed service providers and enterprise IT teams to centrally administer servers, workstations, network devices, software deployment, patching, and remote support functions.

The platform typically operates with elevated privileges and remote access capabilities across customer environments. As a result, compromise of an N-central server can provide access to systems managed through that instance.

N-able previously addressed CVE-2026-18556, a separate authentication bypass vulnerability, in N-central version 2026.2. After investigating active compromise activity in late July, the company determined that threat actors had identified another path to exploit the same underlying flaw. Because the earlier fix did not block this alternative attack path, N-able assigned CVE-2026-18577 to the new finding and released N-central 2026.3.1 Hotfix 1 on August 2. According to N-able, threat actors had already exploited the vulnerability before the updated fix became available.

CVE-2026-18577 allows a remote, unauthenticated threat actor to bypass the normal login process and gain administrative access to a vulnerable N-central server without valid credentials. N-able assigned the vulnerability a CVSS 4.0 score of 8.2 and classified it as high severity.

All versions prior to N-central 2026.3.1.7 (Hotfix 1) are affected.

Researchers reported that threat actors who successfully exploited the vulnerability gained administrative access to N-central servers. They then used the platform's Take Control feature to access managed endpoints, including domain controllers in some observed incidents. Once on those endpoints, the threat actors installed Cloudflare Tunnel as a service to maintain access. Researchers also observed reconnaissance, process enumeration, and lateral movement activity following successful compromise.

At this time, public reporting has not attributed the activity to a known threat actor or group. Though N-able reported that a "limited number" of customers were impacted and contacted directly, the total number of affected organizations has not been disclosed.

Analysis

Vulnerabilities affecting RMM platforms have a long history of attracting threat actor interest because these products:

  • Occupy highly trusted positions within customer environments

  • Often have administrative access to large numbers of systems

CVE-2026-18577 follows a pattern seen in previous incidents involving ConnectWise ScreenConnect, Kaseya VSA, SimpleHelp, and earlier N-central vulnerabilities.

The main concern is the potential access to identity infrastructure and other high-value systems managed through the platform. In this case, researchers observed threat actors accessing managed endpoints, including domain controllers, after compromising vulnerable N-central servers. Successful exploitation involved administrative takeover of N-central servers followed by use of the platform's built-in remote administration capabilities to reach downstream systems.

Mitigations

Organizations using N-central should identify installed versions and upgrade vulnerable deployments to N-central 2026.3.1.7 (Hotfix 1) or later.

Vendor-hosted environments receive updates automatically, while self-hosted deployments require installation of the hotfix.

Patching the N-central server removes the initial access path, but does not automatically remove previously established access to downstream endpoints.

In observed intrusions, threat actors deployed Cloudflare tunnel services on managed systems to maintain access after the N-central server was remediated. Cloudflare Tunnel creates an outbound connection from the endpoint to Cloudflare infrastructure, allowing remote access without requiring an exposed inbound service.

Organizations are advised to review managed endpoints for signs of post-compromise activity. N-able recommends investigating systems for Cloudflare services and suspicious svchost.exe files located in user document directories. These artifacts have been associated with observed intrusions and may indicate that remote access was established on endpoints after compromise of the N-central server.

Additional review activities include:

  • Examining N-central Take Control usage for unauthorized remote access sessions

  • Use published indicators of compromise for threat hunting 

Organizations that identify evidence of unauthorized activity are advised to extend investigations beyond the N-central server to include managed endpoints that may have been accessed during the intrusion.

ThreatRoundUp_SignUp_Simplifiedx2

Stay on top of emerging threats like this.

Sign up to receive a weekly roundup of our security intelligence feed. You'll be the first to know of emerging attack vectors, threats, and vulnerabilities. 

Sign up