N-able has announced a significant security flaw in its N-central remote monitoring and management (RMM) platform. This vulnerability could permit unauthorized users to gain complete administrative access to the console, compromising sensitive operations.
Impact on N-Central Users
The vulnerability affects all supported versions of N-central, whether cloud-hosted or on-premises, and is currently being exploited in real-world scenarios. Known as CVE-2026-18577, this flaw stems from an incomplete fix for a previous issue, CVE-2026-18556, which allowed authentication bypass and account takeover in versions up to 2026.3.1.
This exploit enables remote attackers to access the management platform without credentials, effectively taking on the roles typically reserved for managed service provider (MSP) administrators. Given the widespread use of N-central for monitoring, patching, and remote control of customer endpoints, a single compromised server can lead to a significant supply-chain incident.
N-Able’s Response and Recommendations
In response, N-able has released a hotfix, version 2026.3.1.7, urging immediate upgrades. This update addresses the vulnerability and supports upgrades from versions 2025.4, 2026.1, 2026.2, and 2026.3. Customers using older versions should upgrade to a supported version before applying the hotfix. Huntress has noted that exploitation has already affected some of its clients.
N-able’s investigation highlights the potential misuse of N-central’s Take Control function to infiltrate managed systems, using Cloudflare-based tunnels for persistent access. While full details of the root cause are not yet published, organizations are advised to follow evolving detection guidance.
Security Measures and Monitoring
Administrators are advised to prioritize patching and minimize exposure during upgrades. Public internet access to N-central consoles should be restricted, with access limited through firewall rules, known IP ranges, VPNs, and single sign-on methods. Multi-factor authentication (MFA) should be enforced, although it does not mitigate the authentication-bypass vulnerability.
Security teams should scrutinize N-central activities for irregularities, such as unfamiliar admin accounts, unexpected privilege changes, and unusual remote sessions. Logs related to the Take Control function can be found in the directory C:ProgramDataGetSupportService_N-CentralLogs, but care should be taken as legitimate support activity may also generate these logs.
N-able and Huntress have identified several suspicious IP addresses and domains for further investigation. However, blocking these indicators alone is insufficient, as attackers can swiftly change their infrastructure. Any suspicious N-central console activity should trigger a comprehensive incident response review.
