Critical vulnerability in N-able compromises MSP client networks
N-able confirms attackers exploited 'god mode' flaw in N-central to access client networks; second urgent patch released
August 9, 2026 · 4 min read
TL;DR: N-able confirmed that the CVE-2026-18577 vulnerability in N-central was exploited to access MSP client networks. A second mandatory hotfix has been released, but the lack of details about the scope worries the industry.
On August 7, N-able, a provider of remote monitoring and management (RMM) solutions, confirmed that attackers exploited a critical vulnerability in its N-central platform to access client networks. The flaw, cataloged as CVE-2026-18577, allows an unauthenticated attacker to gain full administrative access to the platform, which in managed service provider (MSP) environments equates to a gateway to all their clients' systems.
What happened?
On July 31, N-able's managed detection and response (MDR) service, Adlumin, detected suspicious activity on a client. The subsequent investigation revealed a zero-day vulnerability being actively exploited on an N-central server. The flaw was officially disclosed and a first hotfix was released on August 2. However, just five days later, N-able published a second mandatory hotfix, version 2026.3.1.10, warning that it is necessary even if the previous one was already applied.
The company confirmed that attackers remotely exploited vulnerable N-central servers and used the platform's 'Take Control' feature to connect to systems within managed environments. Once inside, they registered a Cloudflare tunnel service to maintain persistent access, even after being expelled from the N-central server. This behavior had already been observed by security firm Huntress, and N-able has now corroborated these findings.
Why is this important?
The N-central platform is used by MSPs to manage large numbers of client systems from a single place. This feature makes it an attractive target for cybercriminals: compromising the management platform can provide access to all machines managed by the MSP, rather than just a single server. As Huntress described, a successful exploit grants the attacker the same level of access as trusted network operations and engineering staff.
The urgency of the second hotfix and the inclusion of the vulnerability in CISA's Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of just three days for U.S. federal agencies, underscore the severity of the issue. This unusually short deadline is reserved for vulnerabilities that pose an urgent risk.
Consequences and N-able's response
N-able has confirmed that a 'limited number' of clients were affected, but has not specified how many, nor how many downstream systems the attackers reached, nor what actions they took once they established persistent access. The company did not respond to these questions from The Register, merely stating that it is 'proactively expanding protections in response to continuous monitoring of threat actors as they evolve their attack techniques.'
In addition to the second hotfix, N-able has published 10 IP addresses used in the attacks and a service template for clients to search for known indicators of compromise on Windows endpoints. However, it warns that a clean scan should not be taken as an all-clear signal, as the tool only checks for indicators identified so far, and more may emerge as the investigation continues.
What readers should know
For MSPs running N-central on-premises, the immediate instruction is to install Hotfix 2 without delay. Hosted N-central environments have already received the latest mitigations. It is crucial to understand that the second hotfix is not a repeat of the first; N-able has emphasized that it is necessary even if the previous patch was already applied.
The lack of transparency about the exact scope of the compromise raises concern in the security community. MSPs should assume their environments could be compromised if they have not applied the patches and should conduct thorough searches for indicators of compromise, using tools provided by N-able and other threat intelligence sources.
“This vulnerability is a stark reminder that remote management platforms are high-value targets. A single flaw can compromise multiple organizations through the managed services supply chain.”
Historical context and comparisons
This incident adds to a series of recent attacks against remote management tools, such as the Kaseya case in 2021, where a ransomware attack through its VSA platform affected hundreds of MSPs and over 1,500 businesses. While this incident appears more limited, it underscores the same structural vulnerability: the trust placed in remote management tools and the potential impact on the supply chain.
N-able's rapid response, with a second hotfix in less than a week, indicates that attackers may have found a way to evade the first patch, although this has not been confirmed. The evolution of attack techniques, such as the use of Cloudflare tunnels to maintain access, demonstrates the sophistication of threat actors.
Recommendations for IT professionals
- Immediately install Hotfix 2 (version 2026.3.1.10) on all on-premises N-central servers.
- Review platform access and activity logs for anomalous behavior, especially the use of Take Control and the creation of Cloudflare tunnels.
- Use the indicator of compromise search template provided by N-able, but supplement it with other threat intelligence sources.
- Consider implementing multi-factor authentication (MFA) for all accounts with administrative access to N-central and remote management tools.
- Monitor N-able advisories and organizations like CISA for updates on the investigation and potential new indicators.
In summary, the vulnerability in N-able is a clear reminder of the risks associated with remote management platforms in the MSP ecosystem. The confirmation of access to client networks underscores the need for rapid response and continuous vigilance. While N-able continues its investigation, clients should remain alert and apply all available mitigation measures.