What happened
N-able disclosed on August 1, 2026 that attackers were actively exploiting an authentication bypass vulnerability in N-central, the company's remote monitoring and management (RMM) platform used by managed service providers and enterprise IT teams. The flaw, tracked as CVE-2026-18577, has a CVSS score of 8.2 and lets a remote, unauthenticated attacker bypass login controls and obtain administrative access to an N-central server (Rapid7; Help Net Security).
CVE-2026-18577 is not a new flaw. It is what remained after N-able's own fix for an earlier issue, CVE-2026-18556, proved incomplete. N-able patched CVE-2026-18556 in N-central 2026.2, but attackers found a second path through the same authentication logic that the original fix did not close (Rapid7 vulnerability database). N-able released a hotfix, version 2026.3.1.7 (2026.3 HF1), on August 2 to close the gap (SecurityWeek).
CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on August 3, based on confirmed evidence of active exploitation (CISA). The agency's Binding Operational Directive 26-04 gives federal civilian agencies until August 6 to apply the fix or stop using the product.
Who is affected
All N-central versions before 2026.3.1.7 are vulnerable. N-able said a "limited number of customers" have been confirmed compromised, but declined to give a count or further technical detail (Help Net Security). Security firm Huntress, which independently confirmed exploitation, said many organizations running N-central had not yet patched as of August 3 (Huntress).
The exposure is not limited to the N-central server itself. Because RMM platforms hold administrative reach into every endpoint they manage, a compromised N-central instance gives an attacker a path into the MSP's downstream customer environments, not just the MSP's own infrastructure.
N-able's own account of the intrusions, corroborated by Rapid7, describes attackers using N-central's built-in Take Control feature, meant for legitimate remote support, to connect from a compromised server into managed endpoints. On those endpoints, they placed a file named svchost.exe in a user's Documents folder and registered it as a Windows service called Cloudflared. That service opened an outbound Cloudflare Tunnel connection, a persistence method that needs no inbound firewall rule and, according to N-able, kept working even after access to the N-central server itself was revoked (Rapid7).
Exploitation activity has been observed since August 1, per N-able and CISA.
What affected parties should know
N-able's guidance, echoed by CISA's KEV addition, is to update to N-central 2026.3.1.7 or later immediately. Patching alone does not address a server that has already been breached. N-able and Huntress both recommend organizations also check for the specific indicators tied to this campaign: unexpected Windows services named Cloudflared, unfamiliar files named svchost.exe outside the normal system directory, and unrecognized outbound Cloudflare Tunnel connections from managed endpoints (Huntress).
CISA's directive also points agencies to its forensic triage guidance for any system confirmed to have been reachable through a vulnerable N-central instance, on the basis that a compromised RMM console should be treated as a potential pivot point into every endpoint it manages, not evaluated in isolation.
No advisory reviewed identifies who is behind the exploitation. None of the cited sources attribute the activity to a specific group, and this post does not speculate beyond what they disclose.
What happens next
CISA's remediation deadline for federal agencies is August 6. For MSPs and enterprise IT teams running N-central outside the federal requirement, the practical deadline is now, given that exploitation has already reached customer environments and the attack technique persists independently of the original access point.
N-able has said it is continuing to investigate the scope of the compromise. Whether the August 2 hotfix fully closes the authentication path, given that the prior fix for CVE-2026-18556 did not, is the question worth watching. Organizations running N-central should confirm they are on 2026.3.1.7 and treat any server that was internet-reachable before that update as requiring the endpoint checks above, not just a version bump.
Sources
- Rapid7, "CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild" - https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild/
- Help Net Security, "CVE-2026-18577: N-able N-central vulnerability" - https://www.helpnetsecurity.com/2026/08/03/cve-2026-18577-n-able-n-central-vulnerability/
- CISA, "CISA Adds One Known Exploited Vulnerability to Catalog" - https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog
- SecurityWeek, "N-able Patches Vulnerability Exploited to Hack N-central Servers" - https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/
- Huntress, "N-able Vulnerability Exploitation" - https://www.huntress.com/blog/n-able-vulnerability-exploitation
- Rapid7 Vulnerability Database, CVE-2026-18556 - https://www.rapid7.com/db/vulnerabilities/cve-2026-18556/
