N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
What happened
N-able has released build 2026.3.1.7 to address an authentication bypass vulnerability (CVE-2026-18577) in N-central. The flaw allows attackers to gain remote administrative access to management servers and subsequently compromise managed customer systems.
Why it ranks #1
This is the highest priority due to confirmed active exploitation of a critical authentication bypass in an RMM tool, providing direct enterprise exposure via supply chain access.
Who should care
IT and platform operations, SOC and incident response teams
What to do
Update N-central to build 2026.3.1.7 or later immediately.
- Impact
- high
- Urgency
- near-term
- Confidence
- high
- Scope
- enterprise
- Status
- disclosed