RMM solution provider N-able has disclosed a critical security vulnerability affecting all current versions of its N-central remote monitoring and management platform, including version 2026.3, in both hosted and on-premises deployments.
The flaw, tracked as CVE-2026-18577, allows attackers to gain unauthenticated administrative access to the N-central console, giving them full control over managed environments.
The company released an emergency hotfix (version 2026.3.1.7) on August 2 and is urging all customers to install it as soon as possible. N-able confirmed the vulnerability is being actively exploited in the wild.
Attackers have used the flaw to access managed devices through the Take Control feature and install Cloudflare Tunnel services to maintain persistence even after access to the N-central server was removed.
According to N-able, the issue was discovered during further analysis of the previously patched CVE-2026-18556, which was fixed in version 2026.2. The investigation exposed an additional vector of attack, prompting engineers to develop and release the new fix.
Cybersecurity firm Huntress said it has observed exploitation affecting at least one organization in its customer base. N-able said only a limited number of customers have been confirmed as impacted and that its support team is working directly with affected organizations. The company has also published indicators of compromise (IoCs) and said it will provide further updates as more information becomes available.