Start with Identity
← Blog
News

N-able confirms attackers used an N-central auth bypass to reach managed customer networks

CVE-2026-18577 gave unauthenticated attackers full administrative control of N-central, which they used through the Take Control feature to reach downstream managed endpoints and plant Cloudflare Tunnels for persistence. A second mandatory hotfix landed August 7.

By SWI Community TeamAug 7, 2026Updated Aug 29, 2026

N-able confirmed that attackers exploiting CVE-2026-18577, an unauthenticated bypass granting the administrative privilege level normally reserved for its own network operations staff, used compromised N-central servers to reach the customer networks those servers manage. The chain ran through N-central's Take Control remote session feature onto managed endpoints, then registered new Cloudflare Tunnel services to keep access after N-able evicted them from the N-central instance. N-able's MDR detected suspicious activity on July 31, shipped a first hotfix in 2026.3.1.7 on August 2, and a second mandatory one in 2026.3.1.10 on August 7. CISA added the flaw to KEV on August 6 with a three-day federal deadline.

Why it matters

Remote monitoring and management platforms are the highest-value privileged access targets that most organizations do not treat as such. One N-central server is standing administrative access to every endpoint under it, which is why an authentication bypass there is a many-customer incident rather than a one-server incident. The Cloudflare Tunnel step is the detail to carry into your own hunt: attackers established an independent egress path, so removing them from the management console did not remove them from the network. If you run N-central on-premises, install Hotfix 2 even if Hotfix 1 is applied, check for unexpected tunnel registrations on managed endpoints, review Take Control session logs, and rotate the credentials the platform stores. N-able's negative-result scanner does not clear you.

Source: The Register

Last reviewed By SWI Community TeamSuggest a correctionHow we research
Independent analysis. No vendor sponsorship.