Vulnerability Management

N-able addresses critical N-central vulnerabilities exploited by attackers

As reported by The Hacker News, N-able is addressing critical vulnerabilities in its N-central remote monitoring and management platform that attackers have exploited to gain administrative access and compromise customer systems.

Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrative access to N-central servers. The initial fix for CVE-2026-18556 was incomplete, leading to the discovery of CVE-2026-18577, which affected builds prior to version 2026.3.1.7. Once inside the N-central server, attackers utilized the Take Control feature to access managed endpoints. They then established persistence by registering Cloudflare tunnels as services on these devices, allowing them to maintain access even after the initial N-central connection was revoked.

N-able has released a hotfix, build 2026.3.1.7, and urges all customers to upgrade immediately. Self-hosted servers require manual upgrades, while hosted instances will be updated automatically. Customers who suspect compromise must also manually remove malicious tunnel services from endpoints, as the N-central upgrade alone does not remove this persistence. N-able has not disclosed the number of affected customers or whether data was exfiltrated.

Source: The Hacker News

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds