N-able has released an emergency hotfix for a critical authentication bypass vulnerability affecting its N-central Remote Monitoring and Management (RMM) platform. The flaw, tracked as CVE-2026-18577, is being actively exploited and could allow attackers to gain unauthorized administrative access to vulnerable N-central servers.
The vulnerability affects N-central versions earlier than 2026.3.1.7, making it essential for organizations to update their systems immediately.
Authentication Bypass Leads to Full Administrative Access
The vulnerability allows a remote attacker to bypass the authentication process without valid credentials and take control of user accounts.
Once administrative access is obtained, attackers can fully manage the N-central console and misuse its built-in management capabilities.
Since N-central is widely used by Managed Service Providers (MSPs) to manage customer environments, a successful attack could impact multiple organizations from a single compromised platform.
Potential Impact on MSP Environments
A compromised N-central server can provide attackers with extensive control over managed devices.
Attackers may be able to:
- Execute scripts on managed systems.
- Deploy malicious software or remote access tools.
- Modify automation jobs and security policies.
- Start remote support sessions.
- Access critical servers such as domain controllers and file servers.
Because N-central acts as a centralized management platform, compromising it could allow attackers to move across multiple customer environments.
Active Exploitation Confirmed
Security researchers at Huntress confirmed that the vulnerability has already been exploited in real-world attacks.
The issue was initially associated with CVE-2026-18556, but N-able later clarified that CVE-2026-18577 resulted from an incomplete fix, allowing attackers to bypass authentication and take over accounts.
To address the issue, N-able released N-central 2026.3 Hotfix 1 (version 2026.3.1.7) and recommends verifying installed versions instead of assuming earlier 2026.3 releases are protected.
Recommended Security Measures
Organizations using N-central should take the following actions immediately:
- Upgrade to N-central version 2026.3.1.7 or later.
- Enable Multi-Factor Authentication (MFA) for administrative accounts.
- Restrict access to the management console through VPNs or trusted networks.
- Avoid exposing the N-central console directly to the internet.
- Monitor audit logs and remote access activity for suspicious behavior.
Security teams should also review authentication logs, unexpected remote sessions, and unusual administrative actions to determine whether their environment has been compromised.
Conclusion
The active exploitation of CVE-2026-18577 highlights the risks associated with centralized remote management platforms. Since a single compromised N-central server can provide attackers with broad access across multiple customer environments, organizations should treat this vulnerability as a high priority. Applying the latest hotfix, strengthening access controls, and continuously monitoring administrative activity are critical steps to reducing the risk of compromise.
Indicators of Compromise
| Indicator | Type |
|---|---|
173.249.252[.]200 | IP address |
87.249.138[.]34 | IP address |
37.19.210[.]32 | IP address |
68.235.46[.]214 | IP address |
37.153.90[.]88 | IP address |
92.118.112[.]181 | IP address |
mousears.synology[.]me | Domain |
wagoosh.direct.quickconnect[.]to | Domain |
who-ripped-one.direct.quickconnect[.]to | Domain |