N-able disclosed active exploitation of two related authentication bypass flaws in its N-central remote monitoring and management platform, CVE-2026-18556 and the follow-on CVE-2026-18577, after determining the initial remediation was incomplete. The vulnerabilities, both mapped to CWE-288, allow unauthenticated attackers to take over administrative accounts on vulnerable N-central servers. N-able said attackers gained remote administrator access at a limited number of customer environments, while Huntress reported in-the-wild exploitation affecting both cloud-hosted and on-premises deployments and warned that many exposed servers remained unpatched.
After compromising N-central, attackers abused the platform’s Take Control feature to pivot into managed customer endpoints and, in some cases, installed Cloudflare Tunnel services to maintain persistence even after server access was cut off. Reporting tied the incident to unusual licensing errors seen by some on-premises customers, and community discussions highlighted unexpected unlicensed-server status as a possible indicator. N-able released version 2026.3.1.7 as the first unaffected build and urged immediate upgrading, log review, IOC hunting, and inspection of downstream devices because patching the N-central server alone does not remove persistence already established on managed endpoints.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
18 events from the most recent confirmed update back to the earliest known activity.
CISA added N-able N-central flaw CVE-2026-18577 to its Known Exploited Vulnerabilities catalog after reports of active exploitation and customer compromises. The agency directed Federal Civilian Executive Branch agencies to remediate the issue and review N-central Take Control activity.
Huntress reported that attackers who compromised a self-hosted N-central instance tied to one partner account accessed nine organizations managed by that partner and reached one endpoint in each environment. The report adds a concrete victim-impact count beyond earlier statements that exploitation had been observed in customer environments.
N-able and Huntress published indicators of compromise tied to the attacks, including suspicious IP addresses, domains, and endpoint artifacts such as a Cloudflared service and svchost.exe in users' Documents folders. Huntress also noted that several initially flagged IPs were VPN exit nodes but still relevant to hunting.
Sophos CTU reported a confirmed victim compromised at approximately 08:00 UTC on August 3, 2026, where attackers used a compromised N-central server to access backup servers, domain controllers, and application servers, create a "veeam" domain account, and reset domain administrator passwords. Sophos also said the actor deployed multiple remote management tools including AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, and HopToDesk, and used PhantomKiller to identify and disable security products.
Huntress said telemetry showed confirmed post-exploitation activity in more than one partner environment, with the actor pivoting from compromised N-central access into high-value servers, usually domain controllers. It also observed the intruder immediately pulling process lists on those servers to guide next steps.
Huntress said it had observed exploitation of the N-central vulnerabilities in the wild, including at least one self-hosted partner environment and one organization in its customer base. It warned that compromise could provide full administrative control of the N-central console and downstream managed systems.
N-able confirmed on August 2 that attackers were exploiting CVE-2026-18577, the bypass of the earlier fix. Reporting said the flaw affected both on-premises and cloud-hosted deployments and had impacted a limited number of customers.
Finland's National Cyber Security Centre warned that N-able N-central had a severe, actively exploited vulnerability and stated that all versions available before the emergency hotfix were vulnerable. The alert relayed N-able's guidance to upgrade and noted that affected customers had been contacted.
N-able released hotfix version 2026.3.1.7, also referred to as 2026.3 Hotfix 1, as the first unaffected version for CVE-2026-18577. Customers were urged to upgrade immediately, with hosted instances to be updated automatically and self-hosted deployments requiring manual action.
The CVE record for CVE-2026-18577 was published, describing an incomplete patch for CVE-2026-18556 that still allows authentication bypass and administrative account takeover in N-central. Affected versions were listed through 2026.3, with 2026.3.1.7 identified as unaffected.
N-able determined that the earlier remediation for CVE-2026-18556 was incomplete and that another exploitation path remained. The newly identified bypass was assigned CVE-2026-18577.
N-able stated that exploitation of CVE-2026-18577 had been observed in the wild since August 1, 2026. This establishes that attackers were abusing the incomplete patch bypass before the company publicly disclosed the flaw on August 2.
N-able reported that after taking over N-central servers, attackers used the Take Control feature to access managed devices and then registered a new Cloudflare Tunnel service to maintain persistence after N-central access was blocked.
N-able published a security advisory stating that CVE-2026-18556 had been exploited to gain remote administrator privileges on vulnerable N-central servers. The company said exploitation was identified at a limited number of customers and urged users to upgrade to version 2026.3.
The CVE record for CVE-2026-18556 was published, describing an authentication bypass using an alternate path or channel that can enable unauthenticated administrative account takeover in N-central versions through 2026.1.
N-able began investigating the incident after detecting an unusual volume of licensing errors affecting on-premises N-central customers. Later reporting tied these anomalies to the exploitation activity.
N-able warned that upgrading N-central to the fixed build does not remove attacker-installed Cloudflare tunnel services from already compromised endpoints. The company said customers who suspect compromise must manually remove those malicious services to fully remediate affected devices.
Huntress reported that 55.6% of its partners' and customers' reachable cloud N-central servers were still missing the required hotfix. The company warned that this patching gap was especially concerning because N-central servers often run as appliances without EDR.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
42 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcetheregister.com
Open sourceitpro.com
Open sourcemalware.news
Open sourcecofense.com
Open sourcehuntress.com
Open sourcecwe.mitre.org
Open sourcedocumentation.n-able.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.