Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments.
The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend through its status update page and on an Aug. 2 blog post. N-central is N-able's remote monitoring and management (RMM) platform, used to remotely monitor customer systems and do things like deploy software, scripts, and patches as needed. RMM can also be used to remotely access customer endpoints through the "Take Control" feature.
According to the blog post, N-able on July 31 saw "an increase in licensing issues for our on-premises N‑central customers." Its security teams were engaged to investigate, and on the morning of Aug. 2, personnel found that a previously addressed vulnerability, authentication bypass CVE-2026-18556, contained another vector a threat actor could, and did, exploit to obtain administrative access to vulnerable N-central servers.
"Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment," the disclosure blog post read. "Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked."
N-able's engineering team developed and published a fix to this vulnerability, tracked as CVE-2026-18577 (CVSS score 8.2). The company has identified that a "limited number of customers" have been impacted by the vulnerability to date, and N-able says its support team has engaged these customers directly.
N-able recommends customers not running the most recent version of N-central to upgrade to version 2026.3.1.7. Hosted customers receive the fix automatically, while on-premises customers must apply the fix themselves .
Huntress said in a blog post on Aug. 3 that CVE-2026-18577 remains under active exploitation, and it has seen exploitation impacting one organization in its customer base so far. Moreover, Huntress has seen "many environments" where an N-central Server had not yet been updated to 2026.3.1.7.
Nearly all cloud-hosted servers have been patched as of now. 13.6% of reachable servers remain unpatched , with the majority being self-hosted; 28.6% of reachable N-central self-hosted servers remain unpatched.
John Hammond, senior principal security researcher at Huntress, tells Dark Reading that while telemetry shows confirmed post-exploitation activity in more than one partner environment, there are not yet signs that this has become a broad, indiscriminate campaign across its MSP base.
"In the intrusions we've analyzed, the actor uses N-central access to pivot into high-value servers, usually domain controllers, and immediately pulls a process list to understand what’s running and decide on steps," he explains. "Because a compromised N-central server can push code and tools to many connected endpoints, the potential blast radius is large, so we're treating all vulnerable deployments as high risk even though confirmed exploitation is still limited to a small set of customers."
The stakes for compromise are high, the researchers noted in the blog; a compromised server can be used to "run scripts, push tools, and open remote sessions across every downstream endpoint it manages." The blog post compared it to a kind of "god-mode" you would find in a video game.
Both N-able's disclosure and Huntress' blog post includes indicators of compromise. In addition to patching, Huntress also recommends orgs harden their N-central environment; scan logins, accounts and configurations for "changes and events that do not match your normal operational patterns"; review remote control activity; and assess whether temporarily disabling N-central is appropriate.
N-able has not responded to Dark Reading's request for at press time.
Senior News Writer, Dark Reading
Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Security, Nintendo World Report, and elsewhere.
At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels.
He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today.
The State of Cloud Security: The Latest Challenges
How Organizations Are Managing Incident Response
How Enterprises Are Developing Secure Applications
Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy
Essential News & Insights from Black Hat USA 2025
Experts Explain How to Develop a Framework for Cyber-Fraud Fusion
Prevention at Machine Speed: Hunting Beyond Known Detections
0-Day to 10x Discovery: Security at the Speed of Mythos
When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure
Governing the Agent; Identity Security in the Age of Autonomous AI
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
