N-able fixes N-central auth bypass used in attacks
N-able released patches for CVE-2026-18577, an authentication bypass affecting N-central versions before 2026.3.1.7; attackers used Take Control and a CloudFlare tunnel to persist.
N-able has released patches for CVE-2026-18577, an authentication bypass in its N-central remote monitoring and management product. The flaw affected both on-premises and cloud-hosted deployments and allowed attackers to gain administrative access to servers running versions prior to 2026.3.1.7.
N-able described the vulnerability as a new method to exploit a previously patched issue tracked as CVE-2026-18556. Company telemetry indicates threat actors bypassed the earlier fix and began exploiting the new method in late July. The vendor observed an increase in licensing anomalies on July 31 and confirmed active exploitation on August 2, noting a limited number of customers were impacted.
Attackers used the product’s Take Control remote-access feature to connect to managed devices, then registered a CloudFlare tunnel service on compromised machines to retain access after control of the N-central server was revoked. The incident notice stated: “Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N-central managed environment. Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N-central server was revoked.”
Security firm Huntress confirmed it has observed attacks exploiting CVE-2026-18577 and reported many organizations had not applied fixes as of August 3. Huntress warned that console compromise can grant full administrative access to an N-central console, allowing an actor to push scripts and jobs to many managed endpoints, deploy and run dual-use tools via the N-able agent, initiate remote-control sessions into servers and workstations including domain controllers, and modify roles, accounts and policies to prepare for further activity.
Both N-able and Huntress have published indicators of compromise to help investigators identify affected systems. N-able released the patch in version 2026.3.1.7 and urged administrators to update systems running earlier versions. Huntress’ analysis and customer reports showed many installations remained unpatched in the days after the disclosure.
The activity follows earlier exploitation of N-central vulnerabilities CVE-2025-8875 and CVE-2025-8876 disclosed about a year earlier.








