As reported by The Hacker News, N-able is addressing critical vulnerabilities in its N-central remote monitoring and management platform that attackers have exploited to gain administrative access and compromise customer systems.Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrative access to N-central servers. The initial fix for CVE-2026-18556 was incomplete, leading to the discovery of CVE-2026-18577, which affected builds prior to version 2026.3.1.7. Once inside the N-central server, attackers utilized the Take Control feature to access managed endpoints. They then established persistence by registering Cloudflare tunnels as services on these devices, allowing them to maintain access even after the initial N-central connection was revoked.N-able has released a hotfix, build 2026.3.1.7, and urges all customers to upgrade immediately. Self-hosted servers require manual upgrades, while hosted instances will be updated automatically. Customers who suspect compromise must also manually remove malicious tunnel services from endpoints, as the N-central upgrade alone does not remove this persistence. N-able has not disclosed the number of affected customers or whether data was exfiltrated.Source: The Hacker News
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
