Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-03 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: high ยท severity: not-rated ยท affected_sectors: [] ยท au_impact: true

CVE-2026-18577 โ€” N-able N-central Authentication Bypass

CVE-2026-18577 is an authentication bypass vulnerability in N-able's N-central remote monitoring and management (RMM) platform, exploited by attackers to gain remote administrative access to managed customer systems.

Summary

Attackers exploited CVE-2026-18577 to gain remote administrative access to N-central servers and reach customer systems managed through those servers. N-able's initial fix was incomplete โ€” build 2026.3.1.7 (shipped August 2) is the first unaffected version. After compromising an N-central server, attackers used Take Control to reach managed endpoints and registered Cloudflare tunnels as services on the devices, surviving reboots.

Key Details

  • CVE: CVE-2026-18577
  • Vendor: N-able
  • Product: N-central RMM platform
  • Impact: Remote administrative access, customer system compromise
  • Initial fix: Incomplete
  • Complete fix: Build 2026.3.1.7 (2026-08-02)
  • Post-compromise activity: Cloudflare tunnel persistence, Take Control abuse
  • Source: The Hacker News

Significance

This incident mirrors the SolarWinds pattern of vendors shipping patches that don't fully address the underlying vulnerability. The MSP supply-chain implications are significant โ€” N-able is widely used by managed service providers in Australia, New Zealand, and globally.

Related

References

  • The Hacker News (2026-08-03)