Affected Systems

N-able N-central RMM product, all versions prior to 2026.3.1.7. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both enabling authentication bypass and account takeover. On-premise deployments are affected.

Exploitation Status

Active exploitation confirmed. N-able detected attacks starting July 31, 2026. Threat actors achieved admin access, used Take Control feature to reach managed endpoints, and established persistence via Cloudflare Tunnel services. CISA has flagged both CVEs as actively exploited. Limited number of customers affected.

Business Impact

Attackers gain full administrative access to N-central servers, pivot to managed customer endpoints, and establish persistent backdoors that survive server remediation. MSPs and enterprises using N-central face risk of supply-chain compromise affecting downstream customers. Persistence mechanism (Cloudflare Tunnel service registration) allows continued access even after patching the N-central server itself.

Urgency

🔴 Immediate

Recommended Actions

  • Update on-premise N-central instances to version 2026.3.1.10 immediately; Hotfix 2 supersedes Hotfix 1 and is required even if prior hotfix was applied
  • Deploy N-able's custom service template to scan Windows endpoints for known IoCs; review results alongside manual log analysis and account activity audits
  • Hunt for unauthorized Cloudflare Tunnel services registered on managed endpoints, particularly new services created after July 31, 2026
  • Block or monitor outbound connections to provided IoC IP addresses: 173.249.252.176, 173.249.252.200, 185.156.46.150, 23.234.94.43, 37.153.90.88, 37.19.210.32, 68.235.46.214, 68.235.46.235, 87.249.138.34, 92.118.112.181
  • Review N-central administrative account activity and Take Control session logs for anomalous remote access between July 31 and present