N-able ships N-central hotfix after attackers gain remote admin access

N-able ships N-central hotfix after attackers gain remote admin access

N-able released N-central 2026.3.1.7 after active exploitation enabled remote admin access in MSP environments.

Format News Brief
Read Time 2 min
Category Cyber Security
Updated Aug 03, 2026

N-able has released an emergency hotfix for N-central after its investigation found active exploitation that could give remote attackers administrative access to managed service provider environments. The company says the new fix, version 2026.3.1.7, addresses an alternative path for exploiting a previously patched authentication-bypass issue and is available now to customers.

The incident is consequential because N-central is a remote monitoring and management platform used by MSPs to administer many downstream endpoints. In its August 2 security update, N-able said attackers found a vulnerability affecting N-central servers running versions prior to 2026.3.1.7, obtained remote administrative access, then used the product's Take Control feature to connect to systems inside managed environments. The company also said attackers registered a Cloudflare tunnel service on some devices to preserve access after N-central access was revoked.

What changed

N-able said the investigation began after an unusual rise in licensing issues for on-premises N-central customers on July 31. The company initially recommended upgrading older installations to 2026.3, but later found another exploit method that was not covered by the earlier fix. That led to the 2026.3.1.7 hotfix and a new CVE identifier, CVE-2026-18577.

Security firm Huntress, which published separate guidance after reviewing activity with partners, described the flaw as a critical authentication bypass risk for MSPs because a compromised RMM console can be used to push scripts, open remote-control sessions and alter security-sensitive settings across client networks. Huntress said in an August 3 update that more than half of reachable cloud servers it observed among its partners and customers were still unpatched at that point.

What administrators should do

  • Upgrade N-central deployments to 2026.3.1.7 as the immediate vendor-recommended fix.
  • Restrict access to the N-central console with firewall rules, VPN or other network controls instead of leaving it broadly reachable.
  • Review N-central logins, remote-control sessions, administrative account changes and endpoint activity for signs of unauthorized Take Control use.
  • Check network logs for N-able's published indicators, while treating IP blocking as a partial measure rather than a substitute for patching.

N-able says a limited number of customers have been identified as impacted and that support is engaging those customers directly. For organizations that depend on N-central, the priority is to patch first, then verify whether the management server was used as a route into endpoints or customer environments.

Sources

Cover photo by Vladimir Srajber on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...