Over the weekend, N-able confirmed active exploitation of a new authentication‑bypass flaw (CVE‑2026‑18577) that grants attackers administrator rights. While a patch has been released, a notable share of cloud‑hosted and self‑hosted servers remain unpatched.

Key Takeaways

  • Active exploitation of CVE‑2026‑18577
  • 13.6% of cloud‑hosted servers still unpatched
  • N‑able issued an emergency fix

N‑able disclosed that a threat actor leveraged a patch‑bypass vulnerability (CVE‑2026‑18577) in its N‑central product to obtain administrative access to customer environments. This vector extends the previously addressed CVE‑2026‑18556.

N‑central, the company’s Remote Monitoring and Management (RMM) platform, offers a “Take Control” feature that lets technicians remotely access endpoints. Attackers abused this feature to connect to systems, register a new Cloudflare tunnel, and maintain persistence even after the original server access was revoked.

The engineering team released a fix with a CVSS score of 8.2 (version 2026.3.1.7). Hosted customers receive the update automatically; on‑premises customers must apply it manually.

Security firm Huntress reported that CVE‑2026‑18577 remains under active exploitation, affecting one of its client organizations so far. Their telemetry shows 13.6% of reachable cloud‑hosted servers are still unpatched, while 28.6% of self‑hosted servers lack the fix.

“A compromised N‑central server can push code and tools to dozens of downstream endpoints, dramatically expanding the blast radius,” said Huntress senior researcher John Hammond.

Why This Matters

BozokMedia analysis shows that such “god‑mode” access in MSP ecosystems poses a systemic risk, as a single breached server can compromise multiple client networks, paving the way for data theft or ransomware attacks.

Did You Know?: The “Take Control” feature was originally designed for legitimate remote support, but it has become a prime entry point for attackers.
Server TypeUnpatched Rate
Cloud‑hosted13.6%
Self‑hosted28.6%

Frequently Asked Questions

Q: How do I patch N‑central?
A: Cloud‑hosted users receive the update automatically; on‑premises users must manually upgrade to version 2026.3.1.7.

Q: Are older patch versions still vulnerable?
A: Yes, especially self‑hosted installations where 28.6% remain unpatched, so immediate remediation is critical.