Back to Blog
Cybersecurity August 9, 2026 5 min read

CISA Flags Actively Exploited N-able N-central Flaw After Attackers Breach MSP Customers

CVE-2026-18577, an authentication bypass in N-able N-central rated CVSS 8.2, is being exploited in the wild and has landed in CISA's KEV catalog. Attackers are using the built-in Take Control feature to pivot from RMM servers into managed endpoints.

CISA Flags Actively Exploited N-able N-central Flaw After Attackers Breach MSP Customers

CISA has added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog after confirming that attackers are actively compromising N-able N-central servers — and using them as a springboard into the endpoints those servers manage.

The flaw is an authentication bypass rated CVSS 8.2. It exists because the patch for an earlier vulnerability, CVE-2026-18556 (also 8.2), was incomplete. Every N-central version prior to 2026.3 HF1 is vulnerable. If you run N-central and haven’t applied that hotfix, treat this as an emergency change, not a scheduled one. Federal civilian agencies were ordered to remediate by August 6. That deadline has already passed.

Why this one is worse than the score suggests

N-central is a remote monitoring and management (RMM) platform used by managed service providers. That makes it a force multiplier: whoever controls the N-central server controls every customer endpoint enrolled in it.

That is exactly what’s happening. Attackers who bypass authentication gain administrative access, then abuse N-central’s legitimate Take Control remote-access feature to reach managed machines, run reconnaissance, enumerate processes, and move laterally. In at least one documented case, sessions came in under “MSP Support” — a default username for legitimate Take Control sessions, which makes the activity blend into normal admin noise.

Observed attacker traffic routes through four IP addresses tied to Mullvad and NordVPN exit nodes. N-able acknowledges a “limited number of customers” were compromised but hasn’t put a number on it.

The RMM-as-attack-vector pattern is not new — Kaseya’s 2021 supply chain incident remains the canonical example — but it keeps working because RMM servers sit outside most organizations’ detection focus while holding the keys to everything.

What to do now

  • Upgrade to N-central 2026.3 HF1 immediately. No workaround substitutes for the patch, since the previous fix was itself bypassed.
  • Audit Take Control session logs going back several weeks. Flag sessions from VPN exit nodes and any use of the “MSP Support” account that your team can’t attribute.
  • Rotate credentials for N-central admin accounts and any accounts reachable from managed endpoints.
  • Check for persistence on endpoints that accepted Take Control sessions during the exposure window — attackers were observed deploying persistence mechanisms, not just poking around.

For MSPs, there’s a second-order duty here: your customers inherited this risk. If your N-central server was exposed unpatched, the honest move is proactive notification and endpoint sweeps, not waiting for something to surface.

Sources

cve n-able cisa rmm-security