Critical N-central Auth Bypass CVE-2026-18577 Exploited to Hijack MSP-Managed Endpoints
N-able has warned of active exploitation of a critical authentication bypass vulnerability, CVE-2026-18577, affecting N-central versions prior to 2026.3.1.7, disclosed on August 3, 2026. Attackers exploit the flaw to gain unauthenticated admin access to the N-central management console, then abuse the legitimate Take Control feature to move laterally to customer-managed endpoints, prioritizing high-value targets such as Domain Controllers. Once on an endpoint, threat actors deploy a Cloudflare Tunnel registered as a Windows service, establishing persistent outbound command-and-control that survives reboots, account revocations, and even patching of the N-central server. Because the attack leverages trusted RMM tooling and spoofs identities resembling N-able support accounts, malicious sessions can be difficult to distinguish from legitimate activity. N-able urges immediate upgrade to version 2026.3.1.7, restriction of management console access via VPN or IP allowlist, and deployment of service-creation monitoring and application allowlisting to limit post-exploitation persistence.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in