Affected Systems

N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.

Exploitation Status

Active exploitation confirmed. Attackers gained remote administrative access to N-central servers starting around July 31, 2026. Limited number of customers affected. Attackers deployed Cloudflare tunnels as persistence on managed endpoints. No public PoC disclosed by vendor.

Business Impact

Attackers achieved full administrative access to N-central servers and used Take Control to reach managed customer endpoints. Persistence established via Cloudflare tunnel services survives reboots and N-central upgrades. Initial patch (2026.3) was bypassed; vendor issued CVE-2026-18577 for the incomplete fix. Huntress observed exploitation affecting nine organizations under one partner account, with attackers enumerating processes on endpoints. Scope and data exfiltration remain undisclosed by vendor.

Urgency

🔴 Immediate

Recommended Actions

  • Upgrade all N-central instances to build 2026.3.1.7 immediately. Self-hosted servers require manual upgrade; hosted NCOD instances will be upgraded automatically per vendor schedule.
  • Hunt for malicious Cloudflare tunnel persistence on all managed endpoints: search for svchost.exe in users' Documents folders, services named 'Cloudflared', and outbound Cloudflare tunnel traffic.
  • Review N-central UI logs (ui_access_control.log) and correlate with C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz for unauthorized Take Control sessions, especially those tied to mspsupport@n-able.com or unknown support identities.
  • Block or investigate traffic from attacker IPs: 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, 68.235.46.214 (Mullvad/NordVPN exit nodes).
  • Check for connections to attacker domains: mousears.synology.me, wagoosh.direct.quickconnect.to, who-ripped-one.direct.quickconnect.to. Contact N-able support and engage incident response if any indicators are found.