CVE Tools

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

The Hacker NewsBy The Hacker News

Reported exploitedN-central

Our summary

Attackers exploited a critical authentication bypass vulnerability in N-central, allowing remote administrative access and control over managed endpoints. The flaw, tracked as CVE-2026-18577, affects versions prior to build 2026.3.1.7. An initial patch in 2026.3 proved insufficient, leading to further exploitation that allowed attackers to deploy persistent Cloudflare tunnel services on compromised systems. These tunnels enabled long-term access even after the original entry point was closed. N-able recommends urgent upgrades to 2026.3.1.7 and manual checks for malicious activity on endpoints. Affected organizations are advised to investigate logs and monitor for signs of unauthorized Take Control sessions.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store