Critical N-able N-central Vulnerability Exploited for Remote Takeover

Critical N-able N-central Vulnerability Exploited for Remote Takeover

First seen 3 Aug 2026, 14:53 UTC CybersecuritynewsGbhackersThenextwebwww.kyberturvallisuuskeskus.fiCcb.Belgium.Be+4 85% similarity 78.8

Article Content

Browse articles
ThreatCluster

N-able disclosed a critical vulnerability (CVE-2026-18577) in its N-central RMM platform, allowing unauthenticated attackers to gain administrative control over servers. This flaw affects all versions prior to 2026.3.1.7 and has been actively exploited. The vulnerability stems from an authentication bypass that enables attackers to access the N-central console without valid credentials. Following the discovery of the flaw, N-able released an emergency hotfix on August 2, 2026, urging all customers to upgrade immediately. Cybersecurity firm Huntress reported that exploitation has been observed in the wild, with a significant number of N-central servers still unpatched. The attackers utilized N-central's Take Control feature to access managed endpoints and established Cloudflare tunnels for persistent access. Finland's national cybersecurity center has warned that all versions before the emergency patch are vulnerable.

Key Points: • CVE-2026-18577 allows unauthenticated remote administrative access to N-central servers. • N-able released an emergency hotfix on August 2, 2026, urging immediate upgrades to version 2026.3.1.7. • Exploitation has been confirmed, with attackers using Cloudflare tunnels for persistent access.

ThreatCluster AI How this analysis works

Timeline

2026-08-01
CVE-2026-18556 published
N-able disclosed an authentication bypass vulnerability affecting N-central versions.
Thenextweb
2026-08-02
Emergency hotfix released
N-able issued a hotfix for CVE-2026-18577, urging customers to upgrade to version 2026.3.1.7.
Crn
2026-08-02
Active exploitation confirmed
Huntress reported that attackers are exploiting the vulnerability in the wild, affecting customer organizations.
Crn
2026-08-02
CVE-2026-18577 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-03
N-able warns of ongoing threat
N-able confirmed that the investigation is ongoing and advised all users to update their systems immediately.
Thenextweb

Community

Browse all →