← BACK TO FEED
TAG

n able1 article

N-able's N-central Authentication Bypass Gets Patched Twice After First Fix Left Door Open

Attackers exploited an authentication bypass vulnerability (CVE-2026-18556/CVE-2026-18577) in N-able's N-central remote monitoring platform to gain administrative access to servers and then pivot to managed customer endpoints using the platform's Take Control feature. They also installed persistent Cloudflare tunnels on compromised devices, meaning that simply upgrading N-central is insufficient — customers must also actively hunt for and remove malicious tunnel services. N-able's initial patch proved incomplete, and the fully fixed version (build 2026.3.1.7) was released on August 2, with self-hosted customers required to upgrade manually.

3 Aug 2026