<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=10643465&amp;fmt=gif">

Critical N-Central Flaw Gives Hackers Full Admin Access to MSP Platforms

Critical N-central RMM flaw (CVE-2026-18577) allows attackers full access. Self-hosted partners must patch now to prevent massive supply-chain attacks.
Content Team

N-able has disclosed a critical vulnerability in its N-central RMM platform — tracked as CVE-2026-18577 — that lets unauthenticated attackers gain full administrative access to the console. It is actively being exploited, and it exists because the earlier fix for CVE-2026-18556 left another exploitable path: partners who patched that flaw are not covered.

Every instance not running 2026.3.1 is affected. N-able is upgrading its hosted NCOD instances automatically, with no customer action needed, but self-hosted partners must apply the hotfix themselves.

Because MSPs use N-central to manage thousands of customer endpoints, a single compromised server can trigger a massive supply-chain incident. Attackers can push scripts, deploy tools, and hijack remote sessions across every managed device — including domain controllers.

N-able released hotfix version 2026.3.1.7 on August 2. Patch immediately, restrict console access, enforce MFA, and hunt for the published indicators: a svchost.exe file in managed devices' Documents folders, a registered service named Cloudflared, and any unfamiliar admin accounts or unexpected remote sessions.

Updated 11 Aug 2026: N-able released Hotfix 2 (2026.3.1.10) on 6 August, adding further hardening after identifying a related attack path. It supersedes Hotfix 1 — apply it if you haven't already.

Source: Cybersecurity News

Share this article
Share on facebook Share on linkedin Share on twitter Share on email
blog_book_a_demo_cta_3x
Have questions about protecting your software?
Our escrow experts are standing by to help.
Book a free demo