Critical N-Central Flaw Gives Hackers Full Admin Access to MSP Platforms
Want more insights like this?
N-able has disclosed a critical vulnerability in its N-central RMM platform — tracked as CVE-2026-18577 — that lets unauthenticated attackers gain full administrative access to the console. It is actively being exploited, and it exists because the earlier fix for CVE-2026-18556 left another exploitable path: partners who patched that flaw are not covered.
Every instance not running 2026.3.1 is affected. N-able is upgrading its hosted NCOD instances automatically, with no customer action needed, but self-hosted partners must apply the hotfix themselves.
Because MSPs use N-central to manage thousands of customer endpoints, a single compromised server can trigger a massive supply-chain incident. Attackers can push scripts, deploy tools, and hijack remote sessions across every managed device — including domain controllers.
N-able released hotfix version 2026.3.1.7 on August 2. Patch immediately, restrict console access, enforce MFA, and hunt for the published indicators: a svchost.exe file in managed devices' Documents folders, a registered service named Cloudflared, and any unfamiliar admin accounts or unexpected remote sessions.
Updated 11 Aug 2026: N-able released Hotfix 2 (2026.3.1.10) on 6 August, adding further hardening after identifying a related attack path. It supersedes Hotfix 1 — apply it if you haven't already.
Source: Cybersecurity News