Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-03 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: high ยท affected_sectors: [] ยท au_impact: true

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

Summary

N-able disclosed that attackers exploited an authentication bypass in N-central (CVE-2026-18577) to gain remote administrative access and reach customer systems managed through those servers. Its first fix was incomplete โ€” build 2026.3.1.7 (shipped August 2) is the first unaffected version.

Key Details

  • Date: 2026-08-03
  • Vendor: N-able
  • Product: N-central RMM platform
  • Vulnerability: Cve 2026 18577 Nable Ncentral Auth Bypass โ€” Authentication bypass
  • Initial fix: Incomplete (first patch did not fully address the vulnerability)
  • Complete fix: Build 2026.3.1.7 (2026-08-02)
  • Post-compromise TTPs:
  • Take Control feature used to reach managed endpoints
  • Cloudflare tunnels registered as services on compromised devices
  • Persistence surviving reboots
  • Source: The Hacker News
  • Reliability: Tier 2/4 โ€” Established cyber journalism

Significance

This is a significant MSP supply chain incident. N-able is widely used by managed service providers in Australia and New Zealand. The incomplete fix mirrors the SolarWinds pattern of vendors shipping patches that don't fully address the underlying vulnerability. The use of Cloudflare tunnels for persistence is a notable evasion technique โ€” nothing in the disclosure suggests Cloudflare itself was compromised.

Related

References