N-ABLE has identified a critical authentication bypass vulnerability, CVE-2026-18577, affecting its N-central remote monitoring and management platform. Attackers exploited this flaw to gain unauthorized administrator access to customer environments, enabling them to connect to internal systems and establish persistent access. Although the vulnerability was patched in version 2026.3.1.7, a significant percentage of self-hosted servers remain unpatched.
N-able recommends immediate upgrades for affected customers and cautions that exploitation continues in some cases. Despite the severity, confirmed exploitation appears limited to a small number of organizations.