Critical N-Central Flaw Gives Hackers Full Admin Access to MSP Platforms
Want more insights like this?
N-able has disclosed a critical vulnerability in its N-central RMM platform — tracked as CVE-2026-18577 — that lets unauthenticated attackers gain full administrative access to the console. The flaw affects all supported versions, including cloud and on-premises deployments, and is actively being exploited.
Because MSPs use N-central to manage thousands of customer endpoints, a single compromised server can trigger a massive supply-chain incident. Attackers can push scripts, deploy tools, and hijack remote sessions across every managed device.
N-able released hotfix version 2026.3.1.7 on August 2. Patch immediately, restrict console access, enforce MFA, and monitor for unfamiliar admin accounts or unexpected remote sessions.
Source: Cybersecurity News