Bottom line: N-able reports active exploitation of the authentication bypass vulnerability CVE-2026-18577 in hosted and on-premises N-central servers.
N-able has informed customers that attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in the RMM platform N-central. Both hosted and on-premises installations are affected.
N-able has warned its customers that the security vulnerability CVE-2026-18577 in N-central is already being actively exploited in attacks. The vulnerability allows an authentication bypass and affects both N-able’s own hosted cloud instances and on-premises deployments of the RMM (Remote Monitoring and Management) software. Details on attack paths, affected version ranges, or a CVSS score have not yet been fully disclosed by N-able.
N-central is used by Managed Service Providers (MSPs) to centrally monitor and manage endpoints, servers, and networks across customer environments. Successful exploitation of an authentication bypass vulnerability in such a platform can potentially give attackers administrative access to the managed infrastructure of multiple downstream customer organizations simultaneously. This incident thus joins a series of supply-chain-relevant vulnerabilities in RMM tools that have repeatedly been used in the past as an entry point for broad attacks on MSP customer chains.
CISOs whose organization operates N-central itself or uses it through an MSP should promptly determine whether their instance is affected, apply available patches or mitigations from N-able as soon as possible, and check the access logs of their N-central environment for anomalies. Since exploitation is already being observed in the field, heightened time pressure for remediation should be assumed.
Source: www.bleepingcomputer.com · Published August 3, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.