CVECVE-2026-18577
CVSS 8.2
TypePatch bypass of
CVE-2026-18556
KEV addedAugust 3, 2026
Fixed inN-central 2026.3
Hotfix 1 (2026.3.1.7)
On-prem updateManual required
What happened
N-able first noticed unusual licensing errors from on-premises N-central customers on July 31, 2026. Investigation confirmed that attackers had exploited CVE-2026-18556, an authentication bypass rated CVSS 8.2, to gain unauthenticated administrative access to N-central servers running version 2026.1 and earlier. N-able released a first hotfix on August 2, which addressed the known exploit path. By August 3, N-able had identified that attackers found a second route to the same authentication bypass that the first hotfix did not close. That alternate path was assigned CVE-2026-18577, also rated CVSS 8.2, and a second hotfix was released as N-central 2026.3 Hotfix 1, build 2026.3.1.7. CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on August 3. Both hosted and on-premises deployments are affected. Hosted instances received the update automatically. On-premises customers must install the hotfix manually. Huntress, which confirmed seeing attacks exploiting CVE-2026-18577, documented the post-exploitation pattern: attackers log in to the N-central console with administrative rights, use the built-in Take Control feature to open remote-control sessions on managed endpoints, and install a Windows service named Cloudflared that establishes an encrypted outbound Cloudflare tunnel. That tunnel provides persistent command-and-control access to the managed endpoint that survives N-central access revocation, firewall rule changes, and system reboots. N-able published six IP addresses observed in attacks, which Huntress identified as Mullvad and NordVPN exit nodes used to anonymize attacker traffic. N-able has not disclosed the number of customers affected.
Why it matters
N-central is a remote monitoring and management platform used by managed service providers and enterprise IT teams to monitor, patch, and remotely access hundreds to thousands of endpoints from a single console. An attacker with administrative access to N-central does not have access to one compromised server. They have remote-control access to every endpoint under management, including domain controllers, security appliances, and customer environments managed by MSPs on behalf of their clients. The Cloudflare tunnel persistence mechanism compounds this: revoking the attacker's N-central access does not remove the tunnels already installed on managed endpoints. Each tunnel must be identified and removed individually on each affected device.
Don't miss
The patch bypass timeline here is operationally significant. N-able patched CVE-2026-18556 on August 2. Attackers had identified and exploited the alternate path by August 3, the same day CISA added the new CVE to KEV. Organizations that applied the August 2 hotfix and considered themselves remediated were exposed for less than 24 hours before the bypass was confirmed. This is an unusually short gap between patch and bypass confirmation and reflects active attacker analysis of the fix rather than opportunistic scanning. MSPs running N-central should assume the alternate path was being tested from the moment the first hotfix was published and treat any N-central server that was accessible on August 2 as potentially exposed to CVE-2026-18577 even if CVE-2026-18556 was patched.
Potential actions
- Update N-central to 2026.3 Hotfix 1 build 2026.3.1.7 immediately. This is the only version that closes both CVE-2026-18556 and CVE-2026-18577. The August 2 hotfix for CVE-2026-18556 alone is not sufficient. On-premises deployments require a manual update.
- Hunt for Cloudflare tunnel persistence on all endpoints managed through N-central, not just those where Take Control sessions are visible in N-central logs. Check for a Windows service named Cloudflared or a svchost.exe binary located in a user's Documents folder. These are N-able's documented indicators of compromise for post-exploitation persistence.
- Correlate N-central access logs against the six IP addresses N-able published and the Mullvad and NordVPN exit node ranges Huntress identified. Any administrative session originating from VPN exit nodes in those ranges should be treated as potentially attacker-controlled and trigger endpoint investigation for the Cloudflare tunnel indicators.
The Sip
N-able patched the authentication bypass on August 2. Attackers had the alternate path working by August 3. The Cloudflare tunnels they installed on managed endpoints are still there after N-central access is revoked. Update to 2026.3.1.7, then go find the tunnels on the endpoints. The N-central server is not the only thing that needs cleaning.