N-able Releases Critical Patch for Exploited Vulnerability Hacking N-Central Servers

www.news4hackers.com-n-able-releases-critical-patch-for-exploited-vulnerability-hacking-n-central-servers-n-able-releases-critical-patch-for-exploited-vulnerability-hacking-n-central-servers

N-able has issued patches addressing a vulnerability actively exploited by threat actors in its N-central RMM platform.

Vulnerability Details

N-able has issued patches addressing a vulnerability that was actively exploited by threat actors targeting users of its N-central remote monitoring and management (RMM) platform. The flaw, designated as CVE-2026-18577, is an authentication bypass vulnerability that enables unauthorized account takeovers in N-central instances running versions prior to 2026.3.1.7. Both on-premises and cloud-based deployments are affected. The N-central solution is commonly utilized by managed service providers (MSPs) to oversee, update, and remotely access client servers and endpoints.

Exploitation Method

CVE-2026-18577 is not a newly discovered zero-day but represents a novel exploitation method targeting a previously addressed vulnerability, CVE-2026-18556. Threat actors circumvented the existing patch for CVE-2026-18556 and began leveraging the flaw in late July. N-able first observed a surge in licensing-related issues on July 31 and confirmed active exploitation of CVE-2026-18577 by August 2.

Impact and Response

Attackers gained administrative access to compromised N-central servers, allowing them to utilize the platform’s Take Control feature to connect to systems within the managed environment. N-able reported that a “limited number of customers” were impacted, though cybersecurity firm Huntress noted that many organizations had not yet applied the necessary patches as of August 3.

Huntress highlighted the severity of the flaw from an MSP perspective, emphasizing that exploitation could grant attackers full administrative control over the N-central console—equivalent to the privileges of trusted network operations center (NOC) and engineering staff.

Attack Capabilities

Once inside the console, threat actors could execute a range of malicious activities, including deploying scripts and jobs to all managed endpoints, leveraging dual-use tools like remote tunnels or discovery utilities via the N-able agent, initiating remote-control sessions on critical systems such as domain controllers, and altering security configurations to facilitate further attacks.

Indicators of Compromise

Indicators of compromise (IoCs) associated with CVE-2026-18577 have been disclosed by both N-able and Huntress.

Recurrence of Similar Vulnerabilities

This incident follows a similar pattern to vulnerabilities in N-central that were exploited a year earlier, specifically CVE-2025-8875 and CVE-2025-8876. The recurrence underscores the ongoing risks posed by unpatched systems and the importance of timely mitigation.



About Author

en_USEnglish