Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Microsoft is bringing Xbox 360 games to PC

    August 4, 2026

    Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

    August 4, 2026

    Strategy Sells Bitcoin After Five Weeks Without Buying

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Microsoft is bringing Xbox 360 games to PC
    • Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers
    • Strategy Sells Bitcoin After Five Weeks Without Buying
    • How Borneo’s giant trees defy gravity and old scientific theories
    • What Ben Carroll’s cabinet cuts say about his ‘new direction’ for Victoria | Victorian politics
    • Trump has been able to keep oil prices low. But that power may not last forever.
    • Trump, Graham Dominate Senate Race: 5 Takeaways from South Carolina Debate.
    • AI shopping searches surged 200% in one year – and it’s a top priority for commerce leaders now
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments.

    The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend through its status update page and on an Aug. 2 blog post. N-central is N-able’s remote monitoring and management (RMM) platform, used to remotely monitor customer systems and do things like deploy software, scripts, and patches as needed. RMM can also be used to remotely access customer endpoints through the “Take Control” feature.

    According to the blog post, N-able on July 31 saw “an increase in licensing issues for our on-premises N‑central customers.” Its security teams were engaged to investigate, and on the morning of Aug. 2, personnel found that a previously addressed vulnerability, authentication bypass CVE-2026-18556, contained another vector a threat actor could, and did, exploit to obtain administrative access to vulnerable N-central servers.

    Related:‘Certighost’ Flaw Haunts Microsoft Active Directory Certificates

    “Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment,” the disclosure blog post read. “Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.”

    N-able’s engineering team developed and published a fix to this vulnerability, tracked as CVE-2026-18577 (CVSS score 8.2). The company has identified that a “limited number of customers” have been impacted by the vulnerability to date, and N-able says its support team has engaged these customers directly.

    Upgrade and Lock Down Your N-central Instances

    N-able recommends customers not running the most recent version of N-central to upgrade to version 2026.3.1.7. Hosted customers receive the fix automatically, while on-premises customers must apply the fix themselves.

    Huntress said in a blog post on Aug. 3 that CVE-2026-18577 remains under active exploitation, and it has seen exploitation impacting one organization in its customer base so far. Moreover, Huntress has seen “many environments” where an N-central Server had not yet been updated to 2026.3.1.7.

    Nearly all cloud-hosted servers have been patched as of now. 13.6% of reachable servers remain unpatched, with the majority being self-hosted; 28.6% of reachable N-central self-hosted servers remain unpatched.

    Related:Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII

    John Hammond, senior principal security researcher at Huntress, tells Dark Reading that while telemetry shows confirmed post-exploitation activity in more than one partner environment, there are not yet signs that this has become a broad, indiscriminate campaign across its MSP base.

    “In the intrusions we’ve analyzed, the actor uses N-central access to pivot into high-value servers, usually domain controllers, and immediately pulls a process list to understand what’s running and decide on next steps,” he explains. “Because a compromised N-central server can push code and tools to many connected endpoints, the potential blast radius is large, so we’re treating all vulnerable deployments as high risk even though confirmed exploitation is still limited to a small set of customers.”

    The stakes for compromise are high, the researchers noted in the blog; a compromised server can be used to “run scripts, push tools, and open remote sessions across every downstream endpoint it manages.” The blog post compared it to a kind of “god-mode” you would find in a video game.

    Both N-able’s disclosure and Huntress’ blog post includes indicators of compromise. In addition to patching, Huntress also recommends orgs harden their N-central environment; scan logins, accounts and configurations for “changes and events that do not match your normal operational patterns”; review remote control activity; and assess whether temporarily disabling N-central is appropriate.

    Related:25 Years After Code Red: What the Worm Era Can Teach Us About AI Security

    N-able has not responded to Dark Reading’s request for comment at press time.

    Attackers Bypass exploit Flaw Nable patch RMM Servers
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts

    INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

    Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

    Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Microsoft is bringing Xbox 360 games to PC

    August 4, 2026

    Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

    August 4, 2026

    Strategy Sells Bitcoin After Five Weeks Without Buying

    August 4, 2026

    How Borneo’s giant trees defy gravity and old scientific theories

    August 4, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Microsoft is bringing Xbox 360 games to PC

    August 4, 2026

    Microsoft Bug Bounty Program: $20 Million Paid to 500 Researchers

    August 4, 2026

    Strategy Sells Bitcoin After Five Weeks Without Buying

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.