Thenextweb
Critical N-able N-central Vulnerability Exploited for Remote Takeover
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
N-able disclosed a critical vulnerability (CVE-2026-18577) in its N-central RMM platform, allowing unauthenticated attackers to gain administrative control over servers. This flaw affects all versions prior to 2026.3.1.7 and has been actively exploited. The vulnerability stems from an authentication bypass that enables attackers to access the N-central console without valid credentials. Following the discovery of the flaw, N-able released an emergency hotfix on August 2, 2026, urging all customers to upgrade immediately. Cybersecurity firm Huntress reported that exploitation has been observed in the wild, with a significant number of N-central servers still unpatched. The attackers utilized N-central's Take Control feature to access managed endpoints and established Cloudflare tunnels for persistent access. Finland's national cybersecurity center has warned that all versions before the emergency patch are vulnerable.
Key Points: • CVE-2026-18577 allows unauthenticated remote administrative access to N-central servers. • N-able released an emergency hotfix on August 2, 2026, urging immediate upgrades to version 2026.3.1.7. • Exploitation has been confirmed, with attackers using Cloudflare tunnels for persistent access.