Critical N-Able N-Central Vulnerability Grants Unauthenticated 'God-Mode' Access
A critical vulnerability (CVE-2026-18577) in N-able N-central allows unauthenticated attackers god-mode access to the RMM console, posing a significant supply-chain risk.

N-able has disclosed a critical security vulnerability, tracked as CVE-2026-18577, within its widely-used N-central remote monitoring and management (RMM) platform. This flaw permits unauthenticated attackers to gain complete administrative, or "god-mode," access to the RMM console. The vulnerability affects all currently supported versions of N-central, impacting both cloud-hosted and on-premises deployments. Crucially, this issue is already being actively exploited in the wild, raising immediate concerns for managed service providers (MSPs) and their downstream clients.
The technical details suggest that this vulnerability may be related to an incomplete fix for a previous issue, CVE-2026-18556. According to reports, the prior patch may have inadvertently enabled authentication bypass and account takeover capabilities. This means a remote attacker could potentially bypass credential checks entirely and assume the high-level privileges normally reserved for MSP administrators and engineering teams.
N-central is a vital tool for MSPs, enabling them to monitor, patch, automate, and remotely control customer endpoints. A compromise of an N-central server can therefore trigger a high-impact supply-chain incident, potentially affecting numerous organizations that rely on the compromised MSP for their IT services. An attacker with console-level access could deploy malicious scripts, install unauthorized tools, create new administrative jobs, alter security policies, or initiate remote control sessions on any server or workstation managed by the platform.
In response to the discovery, N-able released hotfix version 2026.3.1.7 on August 2. This update is designed to address CVE-2026-18577 and is available for customers running versions 2025.4, 2026.1, 2026.2, and 2026.3. N-able strongly urges all customers to upgrade immediately. For those using older versions, a transition to a supported upgrade path is necessary before applying the hotfix.
Security researchers have already observed exploitation attempts targeting at least one organization. Initial investigations indicate that attackers might be leveraging N-central's "Take Control" feature to pivot into managed systems. They may also be deploying Cloudflare-based tunnels to establish persistent access, making detection more challenging. While full root cause details are still emerging, security teams are advised to implement available detection guidance and remain vigilant.
N-able recommends several immediate mitigation steps beyond patching. Organizations should restrict broad public internet access to their N-central consoles by implementing firewall rules, limiting access to known IP ranges, utilizing VPN connections, and enforcing single sign-on where possible. Furthermore, multi-factor authentication (MFA) should be enforced for all N-central accounts, although it's important to note that MFA alone does not fully mitigate authentication-bypass vulnerabilities.
Security teams should meticulously review N-central logs for suspicious activities. Key indicators include the creation of unfamiliar administrator accounts, unexpected privilege modifications, the execution of large automation jobs, unusual login times, and remote sessions targeting critical infrastructure like domain controllers or file servers. Specific log files related to Take Control activity can be found in the C:\ProgramData\GetSupportService_N-Central\Logs\ directory.
While N-able and researchers have shared a list of suspicious IP addresses and domains, defenders should not rely solely on blocking these indicators, as attackers can quickly change their infrastructure. Any suspicious connection to an N-central console should trigger a thorough incident response review, assessing affected endpoints, accounts, scripts, and remote sessions to understand the full scope of any potential intrusion.
N-able has released an updated fix, build 2026.3.1.7, addressing an incomplete initial patch for CVE-2026-18577. Attackers exploited the authentication bypass vulnerability to gain administrative access and subsequently used the Take Control feature to compromise customer endpoints, registering Cloudflare tunnels for persistent access. Customers must upgrade to the new build, as the previous recommendation of upgrading to 2026.3 is no longer sufficient, and self-hosted servers require manual updates.