Threat actors have bypassed N‑able’s patch for CVE‑2026‑18556, exploiting the new CVE‑2026‑18577 to gain admin control over N‑central servers. The breach affects both on‑premise and cloud deployments, with limited but growing customer impact.

Key Takeaways

  • Threat actors bypassed the CVE‑2026‑18556 patch
  • CVE‑2026‑18577 grants admin access to N‑central servers
  • Both on‑premise and cloud deployments are affected

Patch Bypass Unveiled

N‑able recently released a security patch for its RMM product N‑central, but threat actors discovered a way to bypass the same patch and exploit CVE‑2026‑18577. The vulnerability, an authentication bypass, impacts all versions prior to 2026.3.1.7 across on‑premise and cloud environments.

Timeline of the Attack

Actors began exploiting the bypass in late July after circumventing the CVE‑2026‑18556 fix. N‑able observed a spike in licensing issues on July 31 and confirmed active exploitation of CVE‑2026‑18577 on August 2.

Affected Capabilities and Risks

Once inside, attackers used the “Take Control” feature to connect to systems within the managed environment, registering a new CloudFlare tunnel service for persistence. Huntress notes many organizations had not yet applied the patch as of August 3.

Why This Matters

BozokMedia analysis shows that a compromised N‑central console gives attackers full administrative rights, enabling them to push malicious scripts, deploy remote tunnels, and access critical domain controllers, dramatically widening the attack surface.

"A bypass‑based exploit underscores the need to reassess security architectures for remote management tools," says cybersecurity expert Dr. Maya Patel.
Did You Know?: N‑central has been a leading RMM solution for MSPs since 2015, but its complexity often makes patch management challenging.

Frequently Asked Questions

Q1: Does the existing patch fully remediate CVE‑2026‑18556?
A: Yes, but bypass techniques can still expose the system, so additional hardening is required.

Q2: What immediate steps should my organization take?
A: Upgrade all N‑central installations to version 2026.3.1.7 or later and monitor network traffic for unauthorized CloudFlare tunnels.