Breaking: N-able N-central RMM Compromised — Active Exploitation with Customer Impact — 3 August 2026
N-able N-central RMM Compromised — Active Exploitation with Downstream Customer Impact
N-able N-central Authentication Bypass Under Active Exploitation
N-able disclosed on August 1 that its N-central remote monitoring and management (RMM) platform is under active exploitation. The vulnerability, CVE-2026-18577, is an authentication bypass that allows unauthenticated remote attackers to gain full administrative access to N-central servers. The original flaw (CVE-2026-18556) was supposedly patched in version 2026.2, but N-able discovered an alternate exploitation path that the initial fix did not block — making this an incomplete patch scenario that extends the affected range to all builds prior to 2026.3.1.7, released August 2.
Attack Chain: From RMM Takeover to Persistent Endpoint Access
The attack sequence is straightforward and dangerous. An attacker authenticates to the N-central web console using the authentication bypass, escalates to full administrative privileges, then uses the built-in Take Control feature to pivot into managed endpoints. From there, they register Cloudflare tunnels (cloudflared) as persistent services on compromised machines, establishing outbound connections that survive reboots and require no inbound firewall rules. N-able confirmed attackers reached downstream customer systems through compromised N-central servers.
Huntress, which published its rapid response analysis on August 3, confirmed exploitation within at least one partner environment, where attackers accessed nine organisations and enumerated processes on endpoints. The initial patch was insufficient; any N-central server not running build 2026.3.1.7 remains vulnerable.
Incomplete Patch, Incomplete Disclosure
N-able has not disclosed the number of affected customers, how many downstream devices were reached, when exploitation began, or who is behind it. The four IP addresses initially published as indicators of compromise turned out to be VPN exit nodes (Mullvad and NordVPN), though two additional addresses were later added. N-able began investigating after an unusual volume of licensing errors from on-premises customers on July 31. Finland's national cyber security centre issued its own advisory on August 2 stating all versions available before the emergency hotfix were vulnerable.
MSP Supply Chain Risk
This is a supply-chain compromise by another name. N-central is the central management platform MSPs use to monitor, patch, and remotely access every customer endpoint. A compromised N-central server gives an attacker the same control as a trusted NOC engineer — the ability to push scripts, deploy tools, initiate remote sessions to domain controllers, and modify security configurations across every customer simultaneously. More than 55% of Huntress's partner N-central cloud servers were still unpatched as of August 3.
So What / Action
If you run N-able N-central or are an MSP customer whose provider uses it, treat this as an active incident, not a patching exercise. Upgrade to build 2026.3.1.7 immediately — versions 2026.3 and earlier are insufficient. Restrict N-central console access to known IP ranges and enforce MFA on all accounts. Audit Take Control session logs for connections from unexpected IPs, unusual hours, or support accounts (e.g., mspsupport@n-able.com). Hunt for Cloudflare tunnel services (cloudflared.exe) on managed endpoints, svchost.exe in user Documents folders, and traffic from the published IOC IPs. If your MSP uses N-central, ask them directly whether they've applied the 2026.3.1.7 hotfix and what their compromise assessment shows — because a compromised RMM server gives an attacker the keys to every downstream customer's environment.

