N-able N-central CVE-2026-18577 Zero-Day Exploited to Hijack RMM Servers
N-able has confirmed active exploitation of a critical authentication bypass vulnerability affecting its N-central remote monitoring and management (RMM) platform, raising significant concerns for managed service providers (MSPs) and organizations relying on the software to administer large fleets of endpoints.
Tracked as CVE-2026-18577, the vulnerability affects N-central versions through 2026.3.1 and could allow an unauthenticated remote attacker to gain administrative control of vulnerable N-central servers.
The vulnerability has been classified under CWE-288, Authentication Bypass Using an Alternate Path or Channel, and carries a CVSS base score of 8.2.
N-able N-central CVE-2026-18577 Zero-Day
The security issue is particularly concerning because CVE-2026-18577 reportedly resulted from an incomplete remediation of an earlier vulnerability, CVE-2026-18556.
N-able initially believed the previous weakness had been addressed in N-central 2026.2. However, attackers subsequently discovered an alternative route capable of bypassing the implemented security controls.
The issue came to light after N-able investigated an increase in licensing anomalies reported by on-premises customers on July 31, 2026.
The investigation revealed activity consistent with attackers obtaining unauthorized administrative-level access to affected N-central installations.
According to N-able’s incident information, an unauthenticated attacker could remotely obtain administrative privileges on N-central servers running vulnerable versions prior to the company’s updated hotfix.
Such access is especially dangerous in an RMM environment because the management server is inherently trusted to communicate with numerous downstream systems.
Attackers exploited N-central’s legitimate “Take Control” remote-support functionality to establish connections to managed endpoints, effectively turning an administrative feature into a mechanism for moving deeper into customer networks.
The threat did not end after attackers compromised the central management platform. On affected Windows endpoints, attackers reportedly registered a Cloudflare tunnel as a Windows service.
This technique provides an independent persistence channel that may remain operational even after administrators patch, rebuild, or wipe the compromised N-central server.
Consequently, organizations cannot assume that updating the central RMM instance completely removes the intrusion. Security teams must separately investigate managed endpoints for persistence mechanisms and other indicators of compromise.
N-able has stated that a limited number of customers were directly impacted and that affected organizations were contacted. Nevertheless, both cloud-hosted and on-premises N-central environments require attention.
Huntress reported on August 3 that more than 55.6% of reachable cloud-hosted N-central servers it observed remained unpatched, highlighting substantial exposure following disclosure.
CISA has also added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog, with an August 6, 2026 remediation deadline under BOD 26-04 guidance.
N-able published several IP addresses associated with the malicious activity, including 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, and 68.235.46.214.
Windows administrators should investigate the C:\ProgramData\GetSupportService_N-Central\Logs\ directory for suspicious BASupSrvc_*.log.gz entries.
Defenders should also inspect user Documents directories for suspicious or renamed svchost.exe files and look for a Windows service named Cloudflared.
N-able is urging customers to immediately upgrade affected N-central installations to hotfix 2026.3.1.7. Organizations should additionally restrict management-console exposure using firewall controls, VPNs, or SSO.
Enforce multi-factor authentication; audit recent Take Control sessions involving domain controllers and other sensitive infrastructure; and deploy N-able’s detection service template to scan endpoints for known indicators.
Because RMM platforms provide privileged access across many systems, rapid remediation combined with endpoint-level threat hunting is essential to prevent compromised management infrastructure from becoming a gateway into entire customer networks.
No Comment! Be the first one.