CISA Flags Actively Exploited N-able N-central Flaw: What MSPs and RMM Users Need to Know
The Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-18577, an actively exploited authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) catalog. N-central is a widely used Remote Monitoring and Management (RMM) platform, the kind of tool managed service providers rely on to administer servers, workstations, and network devices across their client base. That makes this one worth understanding even if you’ve never touched N-central, because it’s a textbook example of the risk every MSP and IT team needs to manage.
What happened
CVE-2026-18577 (CVSS 8.2) lets an unauthenticated remote attacker bypass login and take over administrator accounts on vulnerable N-central servers. It turned out to be an incomplete fix for an earlier flaw, CVE-2026-18556, that N-able had already patched in version 2026.2. Attackers found an alternative path around that fix and began exploiting it in the wild from 1 August 2026.
Once inside, attackers used N-central’s own “Take Control” feature, the same functionality that lets legitimate technicians remotely access managed devices, to pivot from the RMM server into customers’ managed endpoints. They then deployed Cloudflare Tunnel (cloudflared), a legitimate tunnelling tool that’s frequently abused to create hard-to-detect persistent backdoors.
N-able released a hotfix (N-central 2026.3 Hotfix 1, build 2026.3.1.7) on 2 August. Hosted N-central instances were patched automatically; on-premise deployments needed manual action. Despite the urgency, one security vendor reported that more than half of reachable N-central cloud servers remained unpatched days after the fix was available.
Why this matters beyond N-central users
This incident is a near-perfect case study in the risk that comes with any RMM platform: a single compromised management server can become a gateway into every environment it administers. RMM tools are deliberately powerful, they need broad access and elevated privileges to do their job, which is exactly why they are such a high-value target for attackers.
Three details stand out:
- The first patch wasn’t enough. A vulnerability was fixed, but the fix left a related path unaddressed. This is a reminder that “patched” doesn’t always mean “closed,” and that vendors and their customers both need to keep watching a CVE after the first fix ships.
- Legitimate features were the attack path. The attackers didn’t need to write custom malware to reach endpoints; they used the platform’s own remote-control functionality. Any tool with broad administrative reach across an estate deserves scrutiny of exactly what happens if the console itself is compromised.
- The IOC was a legitimate tool. Cloudflare Tunnel is a real, widely used product, which makes it far harder to spot as malicious in network traffic than a bespoke backdoor would be. Detection needs to be based on unexpected use, not just known-bad signatures.
What good RMM security looks like
- Keep management consoles off the public internet where possible, and restrict access with IP allow-lists or a VPN.
- Enforce MFA on every administrative account, including within the RMM platform itself.
- Patch RMM software on an accelerated cycle. These platforms are high-value targets, and a delay of even a few days can matter.
- Monitor for anomalous “Take Control” or remote-access sessions, particularly outside normal working hours or from unexpected accounts.
- Watch for legitimate tools used maliciously. Tunnelling utilities, remote access software, and admin tools are frequently abused precisely because they don’t trigger traditional malware alerts.
- Have a plan for “what if our RMM is compromised.” Because of the access these platforms have, a breach here can cascade into every managed environment, so incident response plans should specifically cover this scenario.
Where System Force IT stands
We don’t use N-able N-central in our own stack, so this specific vulnerability doesn’t affect our clients directly. But the underlying lesson applies to any RMM platform, including our own tooling, which is why we build access controls, patching discipline, and monitoring around the assumption that any single tool with broad administrative reach is a high-value target and needs to be treated that way.
How System Force IT can help
System Force IT provides fully managed IT support and cyber security for businesses across Gloucestershire and the UK, backed by UKAS ISO/IEC 27001 certification. If you would like help with any of the above, our managed IT support team is here for you. Get in touch or call 01452 701355 for a no-obligation chat.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


