N-able has confirmed a breach of its N-central servers after attackers exploited an authentication bypass vulnerability, allowing them unauthorized remote administrative access. This incident, which impacts customer systems managed by these servers, underscores significant security concerns for users of the N-central platform.
Flaw Exploitation and Response
The vulnerability, identified as CVE-2026-18577, affects N-central builds prior to version 2026.3.1.7. N-able released this secure build on August 2, following the realization that their initial fix was insufficient. This platform, widely used by managed service providers and IT teams, is crucial for administering customer endpoints remotely.
Compromised servers enabled attackers to deploy ‘Take Control’ for access to managed endpoints, registering Cloudflare tunnels as services on the devices. These tunnels require no inbound firewall rules, thereby maintaining persistent access even after the initial server route is revoked.
Security Measures and Recommendations
N-able advises all N-central users to upgrade to version 2026.3.1.7 immediately. The previously recommended upgrade to version 2026.3 is now deemed inadequate. Hosted NCOD instances will receive automatic updates, while self-hosted servers need manual upgrades by customers.
In cases of suspected compromise, N-able recommends a thorough search and removal of malicious tunnel services from affected endpoints. Simply upgrading the N-central server is insufficient to clear these persistent threats.
Investigation and Ongoing Concerns
Investigations began on July 31, prompted by unusual licensing errors reported by on-premises customers. The vulnerability, previously recorded as CVE-2026-18556, was thought to be resolved in version 2026.2. However, a new exploitation path was discovered, leading to the reclassification and expansion of affected versions.
The Finnish national cybersecurity center corroborated the vulnerability of all versions before the emergency patch. N-able has released a list of six IP addresses associated with the attacks, which Huntress later identified as VPN exit nodes.
Huntress has also identified domain names used by attackers and highlighted the need for customers to review logs for unauthorized access indications. The firm noted that, in one instance, attackers accessed multiple organizations under a single partner account, though the activity appeared limited to process enumeration.
N-able has yet to disclose the full scope of affected customers or data compromised. The ongoing investigation aims to clarify these details and prevent further security breaches.
