Attackers are actively exploiting an authentication bypass in N-able’s N-central RMM platform (CVE-2026-18577) to take over management servers and pivot into the endpoints they control. N-able released hotfix 2026.3.1.7 on 2 August. If your IT provider runs N-central, this one matters.
What’s happening
N-central is remote monitoring and management (RMM) software used by managed service providers to monitor, patch and remote-control client devices. CVE-2026-18577 lets a remote attacker bypass authentication and gain full admin access to the N-central console — no credentials needed. From there, attackers are using the built-in Take Control feature to jump straight onto managed endpoints and dropping Cloudflare tunnels for persistent backdoor access.
The flaw is actually a bypass of an earlier patch (CVE-2026-18576), which means organisations that thought they were already covered are not. Huntress has confirmed active exploitation is ongoing.
Why this matters for Australian businesses
RMM platforms are the keys to the kingdom in any managed IT environment. A compromised RMM server doesn’t just affect one machine — it gives attackers a direct line into every device that MSP manages. We’ve seen this pattern before with Kaseya VSA, ConnectWise ScreenConnect, and SolarWinds. The difference this time is how quickly the initial patch was bypassed, which says something about the pressure vendors are under to ship fixes fast.
As an MSP ourselves, we audit our own RMM stack against every advisory like this. Businesses that outsource IT should be comfortable asking their provider the same hard questions.
What to do
If you manage your own N-central instance: update to build 2026.3.1.7 immediately and check for indicators of compromise — specifically a service named ‘Cloudflared,’ any instance of ‘svchost.exe’ sitting in a user’s Documents folder, and the four IP addresses listed on N-able’s hotfix page. Hosted N-central customers received the patch automatically, but should still check their environment.
If you use an MSP: ask them whether they run N-central, whether they’ve applied the hotfix, and whether they’ve scanned for the published IOCs. A good provider will welcome the question.
Need a hand reviewing your MSP’s security posture or your own RMM setup? Talk to our team.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
