N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Reported exploitedN-centralOur summary
Attackers exploited a critical authentication bypass vulnerability in N-central, allowing remote administrative access and control over managed endpoints. The flaw, tracked as CVE-2026-18577, affects versions prior to build 2026.3.1.7. An initial patch in 2026.3 proved insufficient, leading to further exploitation that allowed attackers to deploy persistent Cloudflare tunnel services on compromised systems. These tunnels enabled long-term access even after the original entry point was closed. N-able recommends urgent upgrades to 2026.3.1.7 and manual checks for malicious activity on endpoints. Affected organizations are advised to investigate logs and monitor for signs of unauthorized Take Control sessions.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.