N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments.
The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend through its status update page and on an Aug. 2 blog post. N-central is N-able’s remote monitoring and management (RMM) platform, used to remotely monitor customer systems and do things like deploy software, scripts, and patches as needed. RMM can also be used to remotely access customer endpoints through the “Take Control” feature.
According to the blog post, N-able on July 31 saw “an increase in licensing issues for our on-premises N‑central customers.” Its security teams were engaged to investigate, and on the morning of Aug. 2, personnel found that a previously addressed vulnerability, authentication bypass CVE-2026-18556, contained another vector a threat actor could, and did, exploit to obtain administrative access to vulnerable N-central servers.
“Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment,” the disclosure blog post read. “Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked.”
N-able’s engineering team developed and published a fix to this vulnerability, tracked as CVE-2026-18577 (CVSS score 8.2). The company has identified that a “limited number of customers” have been impacted by the vulnerability to date, and N-able says its support team has engaged these customers directly.
Upgrade and Lock Down Your N-central Instances
N-able recommends customers not running the most recent version of N-central to upgrade to version 2026.3.1.7. Hosted customers receive the fix automatically, while on-premises customers must apply the fix themselves.
Huntress said in a blog post on Aug. 3 that CVE-2026-18577 remains under active exploitation, and it has seen exploitation impacting one organization in its customer base so far. Moreover, Huntress has seen “many environments” where an N-central Server had not yet been updated to 2026.3.1.7.
Nearly all cloud-hosted servers have been patched as of now. 13.6% of reachable servers remain unpatched, with the majority being self-hosted; 28.6% of reachable N-central self-hosted servers remain unpatched.
John Hammond, senior principal security researcher at Huntress, tells Dark Reading that while telemetry shows confirmed post-exploitation activity in more than one partner environment, there are not yet signs that this has become a broad, indiscriminate campaign across its MSP base.
“In the intrusions we’ve analyzed, the actor uses N-central access to pivot into high-value servers, usually domain controllers, and immediately pulls a process list to understand what’s running and decide on next steps,” he explains. “Because a compromised N-central server can push code and tools to many connected endpoints, the potential blast radius is large, so we’re treating all vulnerable deployments as high risk even though confirmed exploitation is still limited to a small set of customers.”
The stakes for compromise are high, the researchers noted in the blog; a compromised server can be used to “run scripts, push tools, and open remote sessions across every downstream endpoint it manages.” The blog post compared it to a kind of “god-mode” you would find in a video game.
Both N-able’s disclosure and Huntress’ blog post includes indicators of compromise. In addition to patching, Huntress also recommends orgs harden their N-central environment; scan logins, accounts and configurations for “changes and events that do not match your normal operational patterns”; review remote control activity; and assess whether temporarily disabling N-central is appropriate.
N-able has not responded to Dark Reading’s request for comment at press time.


