N-able N-central Vulnerability CVE-2026-18577 Actively Exploited, Threatening Managed Endpoints
Attackers are actively exploiting CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to gain unauthorized access to managed endpoints via compromised administrator accounts.

Attackers are actively exploiting a critical authentication bypass vulnerability, designated CVE-2026-18577, within N-able N-central, a widely adopted remote monitoring and management (RMM) solution. This flaw allows threat actors to compromise administrator accounts and subsequently gain access to the endpoints managed by service providers.
N-able first detected unusual activity on July 31, 2026, when a significant surge in licensing issues was observed among its on-premises N-central customers. While licensing anomalies are not uncommon, the sheer volume prompted N-able's engineering and security teams to investigate. Their analysis, conducted on August 2, 2026, revealed that a previously addressed vulnerability (CVE-2026-18556), patched in version 2026.2, had a new exploitation vector. The company has assigned CVE-2026-18577 to this newly discovered flaw, confirming that all N-central versions prior to 2026.3.1.7 are affected.
The vendor has automatically applied the necessary hotfix to N-central instances hosted on their cloud infrastructure. However, customers managing their own self-hosted N-central deployments are responsible for manually implementing the patch to secure their environments. N-able reported that a "limited" number of customer installations were breached, with attackers successfully taking over administrative accounts. These compromised accounts were then leveraged to exploit the Take Control feature, enabling the threat actors to establish connections with managed endpoints.
Once inside the managed devices, the attackers demonstrated sophisticated persistence techniques. They registered new services for Cloudflare tunnels, which allowed them to maintain access to the compromised environments even after their initial access to the N-central server was revoked. This tactic highlights the attackers' intent to establish long-term footholds within victim networks.
Managed cybersecurity firm Huntress has corroborated N-able's findings, confirming ongoing exploitation of CVE-2026-18577. Huntress observed exploitation affecting one of its customers and is actively hunting for related activity across its telemetry. Their research indicates a significant patching gap, with over half of their partners' and customers' reachable cloud servers remaining unpatched at the time of their report. This is particularly concerning as N-central servers often run on custom operating systems and may not have endpoint detection and response (EDR) software deployed.
The implications of exploiting RMM tools like N-central are substantial. These platforms are prime targets for attackers seeking to gain a broad reach into numerous organizations or to establish deep access within a single high-value target. The vulnerability grants attackers the same level of control as trusted IT personnel, enabling them to push malicious scripts, deploy dual-use tools, initiate remote control sessions, and alter security configurations to facilitate further malicious activities.
To detect potential compromise, N-able advises customers to inspect managed devices for a file named 'svchost.exe' within the Documents folder and to look for a registered service named 'Cloudflared'. N-able has also provided a list of IP addresses associated with the attackers' activities. Huntress recommends isolating N-central deployments, updating to the patched version, and scrutinizing servers and endpoints for signs of unauthorized access, unusual account modifications, new jobs, or suspicious remote control sessions.
While disabling N-central is a drastic measure, Huntress suggests that organizations, particularly those in high-risk environments or unable to mitigate the exposure, should consciously weigh this option as a temporary safeguard until the hotfix can be applied. The decision to take the RMM offline involves balancing the risk of a compromised central management tool against the loss of critical visibility and remote access capabilities.