N-able has issued a warning to its customers regarding active exploitation of an authentication bypass vulnerability, identified as CVE-2026-18577, affecting its N-central remote monitoring and management (RMM) platform. The flaw impacts both hosted and on-premises N-central servers.
The company released hotfix 2026.3.1.7 on Sunday, August 2nd, to address the security issue. This hotfix is crucial as the vulnerability affects all N-central versions prior to 2026.3. N-able initially disclosed on August 1st that it had detected active exploitation and launched an investigation, which subsequently uncovered additional security concerns across all N-central versions.
N-central is a widely used RMM platform by managed service providers (MSPs) and corporate IT departments for managing diverse systems and network devices. The compromise of these servers could allow attackers to extend their reach beyond N-able's direct customers.
For hosted deployments, the update has already been applied. However, customers operating on-premises instances are required to manually install the hotfix immediately. While N-able agents do not require immediate updates to mitigate CVE-2026-18577, the company recommends updating them for the latest fixes and features.
CVE-2026-18577 is understood to be the result of an incomplete patch for an earlier vulnerability, CVE-2026-18576. The prior flaw, described as an authentication bypass utilizing an alternate path or channel, affected all N-central versions up to 2026.1. Both vulnerabilities could be leveraged for administrative account takeover.
N-able has not released specific technical details about the vulnerability, nor has it provided information regarding the number of customers affected or compromised through CVE-2026-18577. However, the vendor has provided indicators of compromise (IoCs) on the hotfix download page.
These IoCs include four specific IP addresses, the presence of a registered service named "Cloudflared," and an instance of "svchost.exe" found within a user's documents folder. Customers who identify any of these indicators are strongly advised to contact N-able support immediately and engage their internal security teams.
The use of "Cloudflared" is particularly notable, as attackers frequently abuse this legitimate tunneling utility from Cloudflare to establish outbound tunnels. Such tunnels can expose compromised machines or provide remote access without necessitating the opening of inbound firewall ports.
N-able has urged customers to maintain vigilance and closely monitor their environments. The company has also committed to providing further updates as more information becomes available.






