
Attackers have exploited a high-severity vulnerability in N-able’s N-central remote monitoring and management (RMM) platform. The company disclosed the security issue, tracked as CVE-2026-18577, and is urging partners and customers to prioritize available patches immediately. The flaw can enable a remote administrative takeover of the widely used system.
Huntress reported Monday that more than half of reachable N-central cloud servers among its partners and customers had not yet received the hotfix. The vendor said it immediately notified all customers with instructions to upgrade without delay within 24 hours of discovering the impact.
Technical Details of the Flaw
The authentication bypass vulnerability carries a severity score of 8.2 out of 10.0. It does not require privileges or user interaction, although the vulnerability is considered to have high attack complexity. N-able said its investigation determined that an attacker had discovered a way to exploit every N-central server version prior to 2026.3.1.7 and remotely gain administrative access.
Related: Okta to acquire Permiso for identity threat detection
Observed Attacker Behavior
After obtaining administrative access to vulnerable systems, the attackers used the platform’s Take Control remote-access feature to connect to managed systems. They then established Cloudflare tunnels that could maintain access even after the intruders were removed from the server. Huntress described the resulting access as effectively providing an attacker with “god-mode” control of the RMM console.
Such a user with this level of access could potentially create or modify jobs, execute scripts, change accounts and policies, and launch remote sessions into endpoints managed through the platform.
The security firm said it has seen exploitation impacting one organization in its customer base and is continually hunting N-central–related activity.
Recommended Actions
N-able recommends all customers upgrade to the hotfix version immediately.
Related: How Apple beat Netflix with quality focus
The vulnerability bypasses normal authentication.
If your N-central server is still broadly reachable from the internet or other untrusted networks, experts suggest strongly considering temporarily disabling the tool. Users should take the server offline until the hotfix is available and the system can be brought back up behind strict network controls.
N-able said in an email that its investigation is ongoing and providing customers with updated guidance as new information becomes available.
