Canadian Cyber Security Journal
SOCIAL:
Filed under: Featured, TechTalk

N-able N-central CVE-2026-18577: Auth Bypass Exploit Puts MSP-Managed Networks at Risk

What Happened

Threat actors have bypassed the patch N-able issued for CVE-2026-18556 and are now exploiting a new authentication bypass, tracked as CVE-2026-18577, against N-central remote monitoring and management (RMM) servers. N-able confirmed active exploitation on August 2 after initially detecting unusual licensing activity on July 31.

Once attackers gained admin-level access to a target N-central server, they used the platform’s built-in Take Control feature to connect directly to managed endpoints — the devices of N-able’s MSP customers and their clients. They then registered CloudFlare tunnels on compromised systems, establishing persistent network access that survives even after their N-central administrator credentials are revoked.

N-able released hotfix 2026.3.1.7 on August 2. Cybersecurity firm Huntress confirmed attacks exploiting the vulnerability, with many organizations running unpatched versions as of August 3. Both on-premises and cloud-hosted N-central deployments are affected by versions prior to 2026.3.1.7.

Why This Matters for Canadian Organizations

N-central is one of the most widely deployed RMM platforms among Canadian managed service providers. An MSP that runs N-central typically manages the networks, endpoints, and servers of dozens or hundreds of client organizations — including small businesses, municipal governments, healthcare clinics, and professional services firms. A successful attack against the MSP’s N-central instance gives attackers access to that MSP and to every organization under its management umbrella.

This is a supply chain attack at the MSP layer. Attackers do not need to individually compromise each downstream client — they compromise the management platform and reach all clients simultaneously. The CloudFlare tunnel technique means attackers retain access to client environments even after the MSP detects and locks down its N-central server.

Canadian MSPs holding client data face obligations under PIPEDA breach notification rules. Any organization whose network was reachable through a compromised N-central server should treat this as a potential reportable incident. Under OSFI Guideline B-13, federally regulated financial institutions with managed services relationships should assess whether their MSP uses N-central and confirm patch status immediately.

What to Do

Apply hotfix 2026.3.1.7 to all N-central deployments immediately. Do not wait for the next scheduled maintenance window. After patching, audit N-central Take Control logs for unexpected remote sessions and review connected CloudFlare tunnel configurations on managed endpoints. Rotate N-central administrator credentials. If your organization is an MSP client rather than the MSP itself, confirm your provider’s patch status and ask for evidence of a post-incident audit. Contact N-able support if you believe your environment was accessed before patching.

Source: BleepingComputer | Huntress

Enjoy this article? Don’t forget to share.