N-able's first fix for an N-central auth bypass missed a second exploitation path
Attackers used an authentication bypass in N-able's N-central RMM platform to gain administrative access and register persistent Cloudflare tunnels on managed endpoints. N-able's initial patch blocked only one exploitation route; a second CVE covers the one it missed.
N-able disclosed two authentication bypass vulnerabilities in its N-central remote monitoring and management platform. CVE-2026-18556, an unauthenticated administrative account takeover affecting releases through 2026.1, was addressed in 2026.2, but researchers found an alternate way to exploit the same underlying flaw that the fix didn't block, tracked separately as CVE-2026-18577 and fully closed only in build 2026.3.1.7, released August 2. Both score 8.2 on CVSS 4.0. N-able began investigating on July 31 after detecting unusual licensing errors, and security firm Huntress published rapid-response findings on August 3. Attackers who reached administrative access used it to register Cloudflare tunnels as persistent services on managed endpoints, giving them continued access to customer environments even after the N-central server itself was remediated.
Why it matters
An RMM platform's authentication is the perimeter for every endpoint it manages, so an admin-level auth bypass here doesn't stay contained to one server, it's a foothold into every managed customer downstream. The incomplete first fix is the sharper lesson: closing one exploitation path for an authentication flaw isn't the same as closing the vulnerability class, and the Cloudflare tunnel persistence technique means remediating the N-central server alone won't evict an attacker who already got in.
If you run N-central, confirm you're on 2026.3.1.7 specifically, and hunt for unrecognized Cloudflare tunnel registrations on managed endpoints rather than trusting that the server-side patch alone closed the door.
Source: The Hacker News