VYPR
kevPublished Aug 3, 2026· Updated Aug 4, 2026· 6 sources

Critical N-Able N-Central Vulnerability Grants Unauthenticated 'God-Mode' Access

A critical vulnerability (CVE-2026-18577) in N-able N-central allows unauthenticated attackers god-mode access to the RMM console, posing a significant supply-chain risk.

N-able has disclosed a critical security vulnerability, tracked as CVE-2026-18577, within its widely-used N-central remote monitoring and management (RMM) platform. This flaw permits unauthenticated attackers to gain complete administrative, or "god-mode," access to the RMM console. The vulnerability affects all currently supported versions of N-central, impacting both cloud-hosted and on-premises deployments. Crucially, this issue is already being actively exploited in the wild, raising immediate concerns for managed service providers (MSPs) and their downstream clients.

The technical details suggest that this vulnerability may be related to an incomplete fix for a previous issue, CVE-2026-18556. According to reports, the prior patch may have inadvertently enabled authentication bypass and account takeover capabilities. This means a remote attacker could potentially bypass credential checks entirely and assume the high-level privileges normally reserved for MSP administrators and engineering teams.

N-central is a vital tool for MSPs, enabling them to monitor, patch, automate, and remotely control customer endpoints. A compromise of an N-central server can therefore trigger a high-impact supply-chain incident, potentially affecting numerous organizations that rely on the compromised MSP for their IT services. An attacker with console-level access could deploy malicious scripts, install unauthorized tools, create new administrative jobs, alter security policies, or initiate remote control sessions on any server or workstation managed by the platform.

In response to the discovery, N-able released hotfix version 2026.3.1.7 on August 2. This update is designed to address CVE-2026-18577 and is available for customers running versions 2025.4, 2026.1, 2026.2, and 2026.3. N-able strongly urges all customers to upgrade immediately. For those using older versions, a transition to a supported upgrade path is necessary before applying the hotfix.

Security researchers have already observed exploitation attempts targeting at least one organization. Initial investigations indicate that attackers might be leveraging N-central's "Take Control" feature to pivot into managed systems. They may also be deploying Cloudflare-based tunnels to establish persistent access, making detection more challenging. While full root cause details are still emerging, security teams are advised to implement available detection guidance and remain vigilant.

N-able recommends several immediate mitigation steps beyond patching. Organizations should restrict broad public internet access to their N-central consoles by implementing firewall rules, limiting access to known IP ranges, utilizing VPN connections, and enforcing single sign-on where possible. Furthermore, multi-factor authentication (MFA) should be enforced for all N-central accounts, although it's important to note that MFA alone does not fully mitigate authentication-bypass vulnerabilities.

Security teams should meticulously review N-central logs for suspicious activities. Key indicators include the creation of unfamiliar administrator accounts, unexpected privilege modifications, the execution of large automation jobs, unusual login times, and remote sessions targeting critical infrastructure like domain controllers or file servers. Specific log files related to Take Control activity can be found in the C:\ProgramData\GetSupportService_N-Central\Logs\ directory.

While N-able and researchers have shared a list of suspicious IP addresses and domains, defenders should not rely solely on blocking these indicators, as attackers can quickly change their infrastructure. Any suspicious connection to an N-central console should trigger a thorough incident response review, assessing affected endpoints, accounts, scripts, and remote sessions to understand the full scope of any potential intrusion.

N-able has released an updated fix, build 2026.3.1.7, addressing an incomplete initial patch for CVE-2026-18577. Attackers exploited the authentication bypass vulnerability to gain administrative access and subsequently used the Take Control feature to compromise customer endpoints, registering Cloudflare tunnels for persistent access. Customers must upgrade to the new build, as the previous recommendation of upgrading to 2026.3 is no longer sufficient, and self-hosted servers require manual updates.

N-able has released a patch for CVE-2026-18577, a vulnerability that threat actors had been actively exploiting in the wild by bypassing an earlier fix for CVE-2026-18556. The new exploit allowed attackers to gain administrative access to N-central servers, subsequently using the Take Control feature to establish persistence via CloudFlare tunnels even after initial access was revoked.

N-able has released hotfix 2026.3.1.7 to address CVE-2026-18577, an authentication bypass vulnerability that is a regression from a previous patch. The vulnerability affects all N-central versions prior to 2026.3, and while hosted deployments have been updated, on-premises customers must install the hotfix manually. The vendor also provided specific indicators of compromise, including IP addresses and a registered service named 'Cloudflared,' which, if found, warrant immediate contact with N-able support.

The new article from Rapid7 Blog provides additional technical details regarding the exploitation of CVE-2026-18577, noting that attackers have been observed using the vulnerability to deploy Cloudflare Tunnel (cloudflared) for persistent remote access and to compromise downstream managed endpoints. It also specifies that N-able N-central versions up to and including 2026.3.1 prior to Hotfix 1 are affected, with the fixed version being 2026.3.1 Hotfix 1 (2026.3.1.7).

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577 to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to patch the critical N-able N-central flaw within three days. This critical vulnerability, which allows for full administrative access to the N-central console, has been actively exploited since July 31, enabling attackers to pivot into managed endpoints and establish persistent access. Security firm Huntress noted that exploitation could grant attackers the same level of control as trusted NOC and engineering staff, allowing for further malicious activities.

Synthesized by Vypr AI