Dark Reading
Read post

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

Attackers are actively exploiting CVE-2026-18577, a patch bypass vulnerability in N-able's N-central RMM platform, gaining administrator access to vulnerable servers. The flaw is a second vector of a previously patched authentication bypass (CVE-2026-18556). After gaining access, attackers used N-central's Take Control feature to pivot into managed environments, targeting domain controllers and establishing persistence via Cloudflare tunnels. N-able has released a fix in version 2026.3.1.7; on-premises customers must apply it manually. As of reporting, 28.6% of self-hosted N-central servers remain unpatched. Huntress confirmed active exploitation and warns that a compromised N-central server can push code and tools to all connected endpoints, creating a large blast radius. Organizations are advised to patch immediately, harden their N-central environments, and review logs for anomalous activity.

    #security
Aug 03•4m read time•From darkreading.com
Post cover image
1 Impression
Dark Reading's image
Dark Reading

DR (DZone Research) offers insights into software development trends, industry surveys, and technolo...

2.2K Followers

•

745 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard