Bottom line: N-able has revised an insufficient initial patch for the N-central vulnerability CVE-2026-18577, but until the final fix in build 2026.3.1.7 released on August 2, attackers were able to gain administrative control over servers and the customer systems managed through them.
N-able has acknowledged that an initial fix for an authentication bypass vulnerability in its RMM platform N-central was insufficient. Attackers exploited the flaw to gain full administrative control over N-central servers and the customer systems managed through them.
According to N-able, the vulnerability tracked as CVE-2026-18577 allowed attackers to bypass authentication, enabling them to remotely obtain administrative privileges on N-central servers. All N-central builds prior to version 2026.3.1.7 are affected. The vendor initially released a fix, but it proved incomplete, leaving the vulnerability exploitable. Only with build 2026.3.1.7, shipped on August 2, is a version that is actually no longer affected available, according to N-able.
N-central is a remote monitoring and management platform (RMM) through which managed service providers (MSPs) centrally monitor and administer their customers’ IT infrastructure. Successful compromise of such a server potentially gives attackers access to all end-customer systems managed through that instance — a classic supply-chain risk that has repeatedly been exploited in RMM tools in the past.
For CISOs whose organization runs N-central itself, or whose MSP uses this platform, immediate action is required: it should be verified whether the deployed version has actually been updated to 2026.3.1.7 or higher, since the original patch is not considered sufficient. In addition, access logs on N-central servers should be reviewed for signs of unauthorized administrative activity in the period before August 2. If an external MSP is used, it is advisable to directly inquire about the patch status and any indicators of compromise.
Source: thehackernews.com · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.