Skip to content
Threat Feed
high advisory

N-able N-central Authentication Bypass Exploitation

Threat actors are actively exploiting a patch bypass vulnerability (CVE-2026-18577) in N-able N-central to gain administrative control and establish persistent remote access via Cloudflare tunnels.

N-able has identified and released patches for CVE-2026-18577, an authentication bypass vulnerability affecting N-central remote monitoring and management (RMM) software versions prior to 2026.3.1.7. This vulnerability functions as a patch bypass for the previously disclosed CVE-2026-18556. Attackers are actively exploiting this flaw in the wild to achieve full administrative access to on-premises and cloud-hosted N-central consoles. Once inside, attackers leverage the platform's legitimate 'Take Control' feature to pivot into managed environments. To maintain persistence after the initial server-level vulnerability is mitigated, actors have been observed registering new services for Cloudflare tunnels on compromised endpoints. This activity presents a critical risk to Managed Service Providers (MSPs) and their downstream clients, as attackers gain the ability to deploy scripts, run discovery utilities, and initiate remote sessions into sensitive internal systems such as domain controllers.

Attack Chain

  1. Attacker exploits the authentication bypass vulnerability (CVE-2026-18577) in the internet-facing N-central console.
  2. Actor gains administrative access to the N-central console, bypassing existing authentication controls.
  3. Actor utilizes the platform's built-in 'Take Control' feature to initiate remote sessions into managed endpoints.
  4. Actor interacts with managed servers or workstations via the legitimate N-able agent to gain code execution.
  5. Actor executes discovery utilities or dual-use tools to assess the internal environment of the managed system.
  6. Actor installs and registers a new service specifically for a Cloudflare tunnel on the target endpoint.
  7. Actor establishes persistent command and control (C2) channel via the tunnel to maintain environment access.
  8. Actor proceeds with follow-on activities, such as credential harvesting or further lateral movement across the client environment.

Impact

Successful exploitation grants threat actors administrative control over the N-central console, providing the same level of authority as trusted NOC and engineering personnel. Attackers can push arbitrary scripts, deploy dual-use tools, initiate remote-control sessions, and modify security policies across all managed servers and workstations, including highly sensitive infrastructure like domain controllers. This poses a significant supply chain threat, as a single compromised RMM console can compromise an entire downstream customer base.

Recommendation

  • Immediately update all N-central installations to version 2026.3.1.7 or later to address CVE-2026-18577.
  • Review N-central environment logs for any unusual service registrations, specifically looking for new services related to Cloudflare tunnels or unexpected remote management activity.
  • Audit administrative access logs in N-central for unauthorized account usage or atypical login patterns.
  • Investigate managed endpoints for the presence of unauthorized tunnel services or non-standard remote access tools initiated by the N-able agent.

Immediate actions

Patch N-central to 2026.3.1.7

IT Operations 24h

Threat Hunt

Search for new service registrations involving Cloudflare tunnels on endpoints managed by N-able agent

T1543 high high confidence hunt now

Data: Endpoint service creation logs

Mitigations

Restrict N-central console access to known/trusted IP ranges if possible until patching is complete

immediate IT Operations

CVE-2026-18577