<img height="1" width="1" style="display: none" alt="" src="https://px.ads.linkedin.com/collect/?pid=1098858&amp;fmt=gif">

Critical N-Central Flaw Gives Hackers Full Admin Access to MSP Platforms

Critical N-central RMM flaw (CVE-2026-18577) allows attackers full access. Patch now to prevent massive supply-chain attacks.
Content Team

N-able has disclosed a critical vulnerability in its N-central RMM platform — tracked as CVE-2026-18577 — that lets unauthenticated attackers gain full administrative access to the console. The flaw affects all supported versions, including cloud and on-premises deployments, and is actively being exploited.

Because MSPs use N-central to manage thousands of customer endpoints, a single compromised server can trigger a massive supply-chain incident. Attackers can push scripts, deploy tools, and hijack remote sessions across every managed device.

N-able released hotfix version 2026.3.1.7 on August 2. Patch immediately, restrict console access, enforce MFA, and monitor for unfamiliar admin accounts or unexpected remote sessions.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo