Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
🚨 Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
N-able has released an emergency security update for N-central after attackers used an authentication bypass to gain remote administrator access and reach systems managed through affected servers. The attackers then installed Cloudflare tunnels that allowed them to retain access after their route through N-central was blocked. Because N-central gives managed service providers and IT departments control over customer devices, a compromised server can provide access to many endpoints from one administrative console. The platform is commonly used for remote monitoring, patching, maintenance, and technical support.
🕵️♂️ Signs of the Attack
Signs of the campaign first appeared on July 31, when N-able noticed an unusually high number of licensing problems affecting on-premises N-central customers. During that review, N-able found another way to exploit CVE-2026-18556, an authentication bypass it had addressed in N-central 2026.2. The earlier correction blocked one attack route, but did not close an alternative method that could still be used to take over an account without authentication. N-able assigned the new finding CVE-2026-18577 and gave it a CVSS 4.0 score of 8.2 out of 10. The vulnerability affects every N-central build before 2026.3.1.7, according to the company’s security update.
🔍 Inside the N-central Server
Once inside an N-central server, the attackers used its Take Control feature to connect to devices in managed customer environments. They registered Cloudflare tunnels as services on those systems, creating an outside communication route that could survive a reboot and remain active after access through N-central was revoked. Cloudflare itself was not reported as compromised. The attackers abused its tunneling service, which permits outbound connections and can operate without an exposed listening port or new inbound firewall rule. N-able said only a limited number of customers were affected and that its support staff contacted them directly.
⚠️ Important Update for Customers
Customers running N-central 2026.3 are still exposed unless they install the 2026.3.1.7 hotfix released on August 2. Applying the update closes the authentication bypass, but administrators must also check managed endpoints for access created before patching. N-able advised customers to look for a file named svchost.exe in users’ Documents folders, a registered service named Cloudflared, and network traffic involving IP addresses published in its advisory. Any organization finding the listed indicators should contact N-able and investigate the affected endpoints. Removing a malicious tunnel service is necessary because updating the central server will not remove access already established on a separate managed device.