ALITEQ.

n-able's remote-management tool has a hole attackers are already walking through patch now

CVE-2026-18577 lets an attacker skip the login screen entirely and pivot straight into every endpoint N-central manages — CISA added it to its must-patch list within 24 hours.

Priya NairUpdated 1h ago6 min readWeb story
A padlock resting against server hardware, representing an authentication bypass in remote-management software

N-able shipped a hotfix on the afternoon of August 2 for a vulnerability its own customers were actively being hit by. CVE-2026-18577 lets an unauthenticated attacker skip straight past N-central's login screen and land with administrative control over the server that manages every endpoint underneath it. N-able confirmed exploitation had been happening since August 1. CISA added the flaw to its Known Exploited Vulnerabilities catalog the next day — a 24-hour turnaround that tells you how seriously the agency is treating it.

A patch that didn't finish the job

This is the second time in a matter of weeks that N-able has had to patch this same authentication path. CVE-2026-18556 was fixed in version 2026.2 — and then, per N-able's own security update, on the morning of August 2 the company's analysis of a spike in customer licensing anomalies turned up 'another vector to exploit this vulnerability.' The original fix closed one door and left a second one on the same wall. That's assigned as its own CVE, 2026-18577, because from a defender's standpoint it's functionally a new bug — you can be patched against the first one and still be wide open to the second.

How it unfolded

  1. Earlier 2026

    CVE-2026-18556, an N-central authentication bypass, is fixed in version 2026.2.

  2. Jul 31, 2026

    N-able detects an unusual spike in licensing-related anomalies across customer environments.

  3. Aug 1, 2026

    N-able later determines active exploitation of a new bypass vector began on this date.

  4. Aug 2, 2026 (morning)

    Internal analysis identifies the new vector; it's assigned CVE-2026-18577.

  5. Aug 2, 2026 (afternoon)

    N-able ships Hotfix 1 for version 2026.3, bringing affected servers to 2026.3.1.7.

  6. Aug 3, 2026

    CISA adds CVE-2026-18577 to its Known Exploited Vulnerabilities catalog.

What attackers actually did with the access

N-central isn't just another admin panel — it's built specifically to give an MSP or IT team remote control over every device it manages, through a built-in feature called Take Control. That's the whole value of an RMM platform, and it's exactly what makes an authentication bypass on it so much worse than the average one. Per N-able's own writeup, attackers who got in used Take Control to reach systems inside the managed environment directly. When N-able started locking accounts down, at least some attackers had already registered a new Windows service running a Cloudflare Tunnel (cloudflared) — a legitimate tool that gives them a persistent, encrypted way back in that doesn't depend on the N-central account they just lost. N-able says a 'limited number' of customers were affected, though it hasn't published a count.

IT security team monitoring network activity on multiple screens
N-central's job is privileged remote access to managed endpoints — which is exactly why an auth bypass on it is so dangerous. · Unsplash

What to actually do

Check your N-central version — anything at or below 2026.3.1 before Hotfix 1 is exposed.

2

Upgrade to 2026.3.1.7 immediately; don't wait for a maintenance window given confirmed in-the-wild exploitation.

3

Enforce MFA on every N-central account, including service and integration accounts.

4

Audit user access and look for any account created or elevated since July 31.

5

Check for unexpected Windows services referencing cloudflared or an unfamiliar Cloudflare Tunnel.

6

Review Take Control session logs for activity you can't attribute to your own technicians.

Affected vs fixed

Vulnerable

Status
All versions ≤ 2026.3.1, before Hotfix 1

Fixed

Status
2026.3.1.7 (Hotfix 1)

CVSS score

Status
8.2

Federal patch deadline (CISA KEV)

Status
August 6, 2026

Quick answers

Is CVE-2026-18577 being actively exploited?
Yes. N-able confirmed exploitation began August 1, 2026, and CISA added it to its Known Exploited Vulnerabilities catalog on August 3.
Do I need to patch if I already fixed CVE-2026-18556?
Yes — CVE-2026-18577 is a separate bypass vector that the original patch for CVE-2026-18556 didn't close. You need the newer hotfix, version 2026.3.1.7, regardless of whether you patched the earlier one.
What can attackers do once they bypass authentication?
They gain administrative access to the N-central server itself, then can use its built-in Take Control feature to reach every endpoint the platform manages — and plant persistence like a Cloudflare Tunnel service to keep access after the account is locked.
How many customers were affected?
N-able says a limited number of customers have been identified as impacted, but hasn't published an exact count.

If you're an MSP running N-central, this isn't a patch-this-sprint bug — it's a patch-this-afternoon bug, and CISA's 24-hour turnaround to KEV reflects that. The bigger lesson sits one level up: any tool that exists to give one login control over hundreds of machines is a single point of failure by design. That's the same reason a single record-breaking Patch Tuesday still leaves zero-days exploited before the fixes ship — infrastructure software needs a patch cadence that matches the blast radius, not the calendar.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading