TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete patch for an earlier bug left the door open. A hotfix for version 2026.3.1.7 closes the gap.
- CVE: CVE-2026-18577
- CVSS: 8.2 (High · CVSSv4)
- Product: N-able N-central
- Affected: ≤ 2026.3
- Impact: Incomplete patch leads to administrative account takeover
- Status: Exploited in the wild
- Patched in: 2026.3.1.7
- EPSS: 1.5% (30-day)
- Action: Update to 2026.3.1.7 now
Why it matters
N-central is a remote monitoring and management platform used by managed service providers. A N-central account takeover on this platform can cascade into every customer environment it oversees. N-able’s own account of the incident states plainly that “an attacker had identified a vulnerability on all N-central servers running a version prior to 2026.3.1.7, which allowed them to obtain administrative access remotely.”
How the attack works
CVE-2026-18577 is a bypass of the fix N-able shipped earlier for a related flaw, CVE-2026-18556. After gaining administrative access, attackers used the platform’s own Take Control feature to reach managed endpoints. On those devices, they registered a Cloudflare tunnel as a persistent service, allowing continued access even after the N-central server itself was secured.
Running the tunnel as a service means it survives a reboot and needs no open inbound port, since it connects outward to Cloudflare’s network. This N-central account takeover chain therefore extends well past the initial server compromise, reaching into every downstream device the platform manages.
Exploitation status
N-able confirms this N-central account takeover flaw is being exploited in the wild. The company says a limited number of customers have been identified and directly contacted by support.
Affected versions and patch
All N-central servers running versions prior to 2026.3.1.7 are affected. N-able strongly encourages any customer not on the latest build to upgrade immediately. Full details, including indicators of compromise, are available in N-able’s security update from August 2, 2026. The company also recommends enforcing multi-factor authentication and auditing user access as ongoing protection.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.