Exploitation of N-able N-central via CVE-2024-27429
Threat actors are exploiting a remote code execution vulnerability (CVE-2024-27429) in N-able N-central to gain unauthorized access and deploy RMM payloads on managed systems.
CVE search metadata
CVE search record: CVE-2024-27429. KEV: no. Product: N-central. Brief: Exploitation of N-able N-central via CVE-2024-27429. Brief link: https://feed.craftedsignal.io/briefs/2026-08-nable-ncentral-exploitation/
Sophos has identified an ongoing campaign involving the exploitation of a remote code execution (RCE) vulnerability, tracked as CVE-2024-27429, within N-able N-central servers. Attackers are successfully leveraging this vulnerability to gain unauthorized administrative access to the N-central instance. Once the management server is compromised, the threat actors utilize the platform's native Remote Monitoring and Management (RMM) capabilities to push malicious payloads and administrative tools to downstream managed endpoints. This allows the attackers to maintain persistence, conduct further reconnaissance, and establish command-and-control across the target environment. The impact of this activity is significant, as it grants attackers broad control over an organization's entire IT infrastructure managed by the compromised N-central server.
Attack Chain
- Attacker identifies an internet-facing N-able N-central server vulnerable to CVE-2024-27429.
- Attacker sends a crafted exploit request to the target server to execute arbitrary code.
- The N-central server process executes the malicious payload with administrative privileges.
- Attacker leverages the compromised N-central administrative console to distribute RMM agent updates or custom scripts.
- Managed endpoints receive and execute the malicious payloads pushed by the N-central server.
- Malware establishes a persistent connection to attacker-controlled C2 infrastructure.
- Attacker performs lateral movement and exfiltration within the compromised network.
Impact
The exploitation of N-able N-central allows attackers to bypass traditional per-endpoint defenses by using a trusted administrative tool to deploy malware. This campaign directly impacts IT service providers and organizations using N-central for management, granting attackers the ability to compromise an entire fleet of managed endpoints simultaneously. Successful access can lead to total system compromise, data theft, and the deployment of additional ransomware or secondary payloads.
Recommendation
- Patch N-able N-central servers immediately to address CVE-2024-27429.
- Review N-central administrative logs for unauthorized account creation or atypical script deployment tasks.
- Monitor for unexpected processes spawned by the N-central agent service on managed endpoints.
- Audit all active administrative sessions within the N-central management console for anomalies.
Immediate actions
Patch N-central to version containing fix for CVE-2024-27429