Active Exploitation of N-able N-central Authentication Bypass Vulnerability
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
N-able has issued an emergency hotfix for CVE-2026-18577, an authentication bypass vulnerability in its N-central RMM platform, which allows remote, unauthenticated attackers to gain administrative access. This flaw affects all versions prior to 2026.3.1.7 and was actively exploited before the fix was released. Attackers utilized the platform's Take Control feature to access managed endpoints and deployed Cloudflare Tunnel services for persistent access. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog on August 3, 2026. N-able previously addressed a related vulnerability, CVE-2026-18556, but the fix did not prevent this new exploitation path. The vendor has not disclosed specific technical details about the attack vector or the vulnerable endpoint. The situation poses an immediate operational risk to managed service providers and enterprise IT teams using N-central.
Key Points: • CVE-2026-18577 allows unauthenticated remote access to N-central servers. • Attackers exploited the vulnerability before a patch was available, targeting high-value systems. • CISA added the vulnerability to its KEV catalog, highlighting its active exploitation.