N-able Ships Emergency Patch After Attackers Bypass N-central Auth Bypass Fix

CVE-2026-18577 lets attackers bypass an earlier N-central patch to seize admin access on MSP RMM servers, with Huntress observing live exploitation and CloudFlare-tunnel persistence.

N-able Ships Emergency Patch After Attackers Bypass N-central Auth Bypass Fix

N-able has shipped an emergency hotfix for an authentication-bypass flaw in its N-central remote monitoring and management (RMM) platform after threat actors weaponised it to take over MSP servers and pivot into managed customer environments.

A patch bypass, not a new zero-day

Tracked as CVE-2026-18577, the flaw is a fresh exploitation path for the previously patched CVE-2026-18556. N-able's first hotfix, released August 2, closed the primary vector but left an alternate route open, prompting the new CVE. Both on-premises and cloud-hosted N-central versions prior to 2026.3.1.7 are affected.

Timeline: licensing anomalies, then admin takeover

N-able says it noticed a spike in licensing issues on July 31 and confirmed active exploitation of CVE-2026-18577 on August 2. Successful attacks granted admin access to the N-central console, from which threat actors leveraged the built-in Take Control feature to reach downstream devices, then registered a new service for a CloudFlare tunnel to persist even after N-central access was revoked.

MSP RMM console under attacker control

Huntress warns MSPs to patch immediately

Cybersecurity firm Huntress independently confirmed the attacks, cautioning that many organisations had yet to apply the fix as of August 3. Once inside an N-central console, an attacker can push scripts and jobs to managed endpoints, deploy dual-use tools, initiate remote-control sessions to domain controllers, and modify roles or policies to widen access. Both vendors have released indicators of compromise.

The disclosure lands roughly one year after MSPs were warned about earlier N-central bugs and stacks on top of active exploitation of the Arista VeloCloud Orchestrator CVE-2026-16812 and the SonicWall SMA 1000 zero-days.

Reporting based on coverage from SecurityWeek, BleepingComputer, Huntress and N-able's incident notice.

Category: Cyber Security

Tags: Cybersecurity CVE

Related Articles