What is Happening?
N-able has disclosed a critical N-central vulnerability (CVE-2026-18577, after an initial incomplete fix for CVE-2026-18556) affecting all supported versions through 2026.3.1, both cloud and on-prem. It lets an unauthenticated attacker gain full admin access to the console — enabling scripts, software pushes, and remote sessions across every managed endpoint. N-able confirmed active exploitation and released hotfix 2026.3.1.7 on August 2, 2026. Huntress is investigating and has published a blog with detection guidance.
Has this actually been exploited?
Yes. Where exploitation has occurred, the attacker used N-central's built-in Take Control feature to reach downstream endpoints and registered a Cloudflare tunnel as a persistence mechanism. Watch for an unexpected service named "Cloudflared" or a file named svchost.exe in user document directories, as well as Take Control sessions from unfamiliar IPs, odd hours, or unrecognized accounts — especially against domain controllers or other critical systems.
Am I affected?
Check your N-central server version — anything before 2026.3.1.7 is vulnerable. Then review Take Control session logs, check for unexpected admin accounts, new API tokens, or loosened security settings (MFA removed, IP restrictions widened), and look for the Cloudflare tunnel indicators above.
I don't think I even use N-able — why did I get flagged?
The notification list was built from a sweep for leftover N-able Take Control files on disk, so accounts from inherited or migrated clients can get flagged even if the product was uninstalled long ago. If that's your situation, no action is needed beyond confirming N-able isn't actually live in your environment.
What should I do right now if I use N-able?
- Apply N-able's hotfix immediately — upgrade to version 2026.3.1.7.
- Restrict console access — put it behind a VPN or SSO, enforce MFA, and limit inbound access to known IP ranges.
- Review N-central logins and remote-control activity for anything that doesn't match your normal support work.
- If you can't patch right away and your server is publicly accessible, consider temporarily disabling N-central — weigh that against the loss of central visibility and remote access.
-
If you're a Huntress Managed EDR customer, confirm Managed Response isolation and active remediation are enabled so we can contain anything malicious quickly.
What is Huntress doing about this?
We're actively hunting across our telemetry for exploitation behavior, proactively identifying unpatched N-central instances and notifying at-risk partners, tuning detections to separate normal MSP use of N-central from abusive RMM activity, and continuously updating our public blog as the investigation evolves.
Where can I get more information or help?
- Huntress blog (updated regularly): huntress.com/blog/n-able-vulnerability-exploitation
- N-able's official advisory: n-able.com/blog/n-central-security-update-august-2-2026
- N-able status page: uptime.n-able.com
- If you have questions or believe you're affected, reach out to Huntress SOC Support directly.
- Email SOC Support at incidents@huntress.com
- Chat with SOC Support using the 'help' button in the lower left corner.