N-able has released an urgent hotfix for an authentication bypass vulnerability affecting its N-central remote monitoring and management platform.
The N-central auth bypass flaw, tracked as CVE-2026-18577, affects hosted and on-premises servers running versions released before 2026.3. N-able says attackers are actively exploiting the vulnerability.
The company issued hotfix 2026.3.1.7 on Sunday and strongly advised customers to upgrade without delay.
N-able identifies active exploitation
N-able first disclosed the active attacks on 1 August. The company said its investigation also identified additional security concerns affecting N-central, its flagship RMM platform.
N-central helps managed service providers and corporate IT teams manage large groups of systems and network devices. It supports environments that use different operating systems.
As a result, a compromised N-central server can create risks beyond N-able’s direct customers. Attackers could potentially use access to reach managed devices and connected organisations.
Hosted N-central environments have already received the security update. However, customers running N-central on their own infrastructure must install the hotfix manually.
CVE-2026-18577 follows an incomplete patch
CVE-2026-18577 resulted from an incomplete fix for CVE-2026-18576. The earlier flaw affected all N-central versions through 2026.1.
Both vulnerabilities could allow an attacker to bypass authentication through an alternate path or channel. Successful exploitation could lead to the takeover of administrative accounts.
N-able has not released technical details about the new issue. It also has not said how many customers attackers targeted or compromised.
The product has faced serious security issues before. Zero-day attacks against N-central last year prompted the Cybersecurity and Infrastructure Security Agency to issue an urgent alert.
Other major RMM and managed service provider platforms have also attracted attackers. Previous incidents have involved Kaseya VSA, ConnectWise ScreenConnect, SimpleHelp, and SolarWinds Orion.
Customers should check for compromise indicators
N-able published indicators of compromise on the hotfix download page. These include four IP addresses, a registered service called Cloudflared, and a file named svchost.exe in a user’s Documents folder.
Customers who identify any of these signs should contact N-able support immediately. They should also involve their internal security teams.
Cloudflared is a legitimate Cloudflare tunnelling tool. However, attackers often abuse it to create outbound tunnels from compromised systems. These tunnels can provide remote access without requiring inbound firewall ports.
N-able says agents do not need an immediate update to address the N-central auth bypass. Still, the company recommends updating agents to receive the latest fixes and features.
Customers should apply the server hotfix as soon as possible, monitor their environments closely, and review the published indicators for suspicious activity.


0 responses to “N-able Warns of Exploited N-central Auth Bypass Flaw”