Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
mediumDetails
An authentication bypass vulnerability in N-able's N-central remote monitoring and management (RMM) solution is being actively exploited by attackers. The flaw, which was subject to a patch bypass, allows threat actors to gain administrator access to N-central servers, which can then be used to compromise the downstream endpoints of managed service provider (MSP) customers.
Affected Systems
N-able N-central servers (on-premises and hosted).
Potential Impact
Total compromise of MSP-managed environments, leading to a significant supply chain risk. Attackers can gain access to thousands of customer endpoints for ransomware deployment, data theft, or further attacks.
Mitigations
Apply the latest patches from N-able immediately. This vulnerability is on the CISA KEV list, which requires federal agencies to patch exploited vulnerabilities on an accelerated timeline. All organizations using this software should prioritize this patch.