Attackers are actively exploiting CVE-2026-18577, a patch bypass vulnerability in N-able's N-central RMM platform, gaining administrator access to vulnerable servers. The flaw is a second vector of a previously patched authentication bypass (CVE-2026-18556). After gaining access, attackers used N-central's Take Control feature to pivot into managed environments, targeting domain controllers and establishing persistence via Cloudflare tunnels. N-able has released a fix in version 2026.3.1.7; on-premises customers must apply it manually. As of reporting, 28.6% of self-hosted N-central servers remain unpatched. Huntress confirmed active exploitation and warns that a compromised N-central server can push code and tools to all connected endpoints, creating a large blast radius. Organizations are advised to patch immediately, harden their N-central environments, and review logs for anomalous activity.