N‑able Patches Vulnerability Exploited to Hack N-central Servers
Reported exploitedN-able N-centralOur summary
N-able has issued a critical update addressing a recently exploited vulnerability, CVE-2026-18577, impacting its N-central remote monitoring and management (RMM) platform. The flaw allows attackers to bypass authentication, leading to unauthorized access in versions prior to 2026.3.1.7. Cybersecurity researchers reported that threat actors began exploiting this weakness in late July 2026, leveraging it to gain administrative control of compromised systems. Attackers used features like 'Take Control' to infiltrate networks further and establish persistent access through services such as CloudFlare tunnels. Although only a small number of customers have been affected so far, experts warn that many organizations remain unpatched. An updated mitigation guide is now available.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.