A newly disclosed vulnerability in N-able’s N-central platform is being actively exploited to gain administrative access to servers and the computers connected to them.
N-central is a remote monitoring and management platform used by IT providers to maintain customer devices, deploy updates, provide remote support and manage security.
That centralised access makes such platforms extremely useful—but also makes them valuable targets. Compromising one management server may provide a route into numerous computers belonging to the provider’s clients.
N-able says the vulnerability affects N-central servers running versions earlier than 2026.3.1.7. The company released a hotfix on 2 August and is urging customers to update immediately.
How the Attack Works
N-able began investigating after noticing an unusual increase in licensing problems affecting on-premises N-central customers on 31 July.
The company initially believed that a related issue had already been addressed, but its investigation uncovered an alternative method of exploitation. The new vulnerability is now tracked as CVE-2026-18577.
According to N-able, attackers used the vulnerability to obtain remote administrative access to affected N-central servers.
They then used N-central’s legitimate Take Control feature to connect to computers inside managed customer environments. Once inside those devices, the attackers installed a service that created a Cloudflare tunnel. This provided a persistent route back into the environment, even after access to the original N-central server had been removed.
This is an important distinction. The attackers were not simply taking control of one IT-management dashboard. They were using its trusted remote-access capabilities to reach the computers it managed.
CISA Confirms Active Exploitation

The US Cybersecurity and Infrastructure Security Agency added CVE-2026-18577 to its Known Exploited Vulnerabilities catalogue on 3 August.
Vulnerabilities are added to the catalogue when there is evidence that they are being exploited in real-world attacks, rather than existing only as a theoretical security problem.
N-able says only a limited number of customers are currently known to have been affected and that its support team has contacted those organisations directly. However, investigations are continuing and additional indicators of compromise may still be discovered.
Who Needs to Take Action?
Organisations operating their own N-central server should update to version 2026.3.1.7 immediately.
Installing the hotfix closes the known vulnerability, but patching alone may not remove access that an attacker has already established.
Potentially affected organisations should also:
- Review administrator and user activity
- Examine remote-access logs
- Check managed endpoints for unfamiliar services
- Look for unauthorised Cloudflare tunnels
- Rotate sensitive administrative credentials
- Investigate unexpected Take Control sessions
- Confirm that no new persistence mechanisms remain
N-able has released an automated service template to check Windows endpoints for known indicators associated with the attack. However, the company warns that a clean scan does not guarantee that an environment was never compromised.
What Should Small Businesses Ask Their IT Provider?

Many small businesses do not operate N-central themselves. They may still be affected if an external managed service provider uses it to support their computers.
Business owners should ask their IT provider three direct questions:
- Does your company use N-central?
- Has every server been updated to version 2026.3.1.7?
- Have our managed devices been checked for signs of unauthorised access?
A reputable provider should be able to explain whether it uses the affected software, when it applied the hotfix and which additional checks it performed.
For most ordinary home users, no direct action is required unless their computer is remotely managed through an employer, school or outsourced IT-support service.
Why Remote – Management Vulnerabilities Are So Serious
Remote-management platforms operate with extensive privileges because they need to install software, change settings and troubleshoot devices without being physically present.
When they function correctly, they make IT support faster and more efficient. When compromised, those same permissions can give attackers a trusted route past several normal security barriers.
The N-central incident is another reminder that cybersecurity depends not only on the software installed on an individual computer, but also on the tools used by organisations responsible for maintaining it.
Updating the N-central server is the immediate priority.
Checking what happened before the update is just as important.
By Radoslav Jokic
Updated on 4th August 2026