ON August 2, 2026, N-able disclosed CVE-2026-18577, an authentication bypass vulnerability in their N-central platform, allowing remote unauthenticated attackers administrative access to servers. This flaw was exploited in the wild, leveraging features like Take Control and Cloudflare Tunnel for persistent access. Organizations should urgently remediate the issue if running affected versions, with automated upgrades for hosted environments and manual remediation for on-premise ones.
The fixed version is N-central 2026.3.1 Hotfix 1. N-able provided indicators of compromise (IOCs) for investigation, including suspicious network activity and service presence, and advised contacting support if compromises are detected.