N-able confirms attackers used an N-central auth bypass to reach managed customer networks
CVE-2026-18577 gave unauthenticated attackers full administrative control of N-central, which they used through the Take Control feature to reach downstream managed endpoints and plant Cloudflare Tunnels for persistence. A second mandatory hotfix landed August 7.
N-able confirmed that attackers exploiting CVE-2026-18577, an unauthenticated bypass granting the administrative privilege level normally reserved for its own network operations staff, used compromised N-central servers to reach the customer networks those servers manage. The chain ran through N-central's Take Control remote session feature onto managed endpoints, then registered new Cloudflare Tunnel services to keep access after N-able evicted them from the N-central instance. N-able's MDR detected suspicious activity on July 31, shipped a first hotfix in 2026.3.1.7 on August 2, and a second mandatory one in 2026.3.1.10 on August 7. CISA added the flaw to KEV on August 6 with a three-day federal deadline.
Why it matters
Remote monitoring and management platforms are the highest-value privileged access targets that most organizations do not treat as such. One N-central server is standing administrative access to every endpoint under it, which is why an authentication bypass there is a many-customer incident rather than a one-server incident. The Cloudflare Tunnel step is the detail to carry into your own hunt: attackers established an independent egress path, so removing them from the management console did not remove them from the network. If you run N-central on-premises, install Hotfix 2 even if Hotfix 1 is applied, check for unexpected tunnel registrations on managed endpoints, review Take Control session logs, and rotate the credentials the platform stores. N-able's negative-result scanner does not clear you.
Source: The Register
Related on Start with Identity
- BlogN-able's first fix for an N-central auth bypass missed a second exploitation path
Attackers used an authentication bypass in N-able's N-central RMM platform to gain administrative access and register persistent Cloudflare tunnels on managed e
- BlogEvery on-premises TeamCity server is vulnerable to an auth bypass in the agent polling protocol
CVE-2026-63077 lets an unauthenticated attacker abuse TeamCity's agent polling protocol to bypass authentication and run arbitrary OS commands with the server p
- BlogQilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door
Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session w
- CVEN-able N-central auth bypass, incomplete patch of CVE-2026-18556
N-able N-central authentication bypass and account takeover. The first fix (CVE-2026-18556) was incomplete. Actively exploited. CISA added it to KEV on 3 August
- CVEConnectWise ScreenConnect auth bypass via an alternate path
ScreenConnect 23.9.7 and earlier skipped authentication on an alternate setup path (CWE-288). Attackers created admin users within hours. CISA KEV. CVSS 10.0. P
- CVEDrupal Simple OAuth/OIDC auth bypass via an alternate path
Drupal Simple OAuth / OIDC 6.0.0 through 6.0.6 allowed authentication to be skipped on an alternate path. Patched in 6.0.7.