🔴 Critical | Source: The Hacker News
Attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-able’s N-central remote monitoring and management platform to gain full administrative control of affected servers. Because N-central is used to manage customer endpoints at scale, compromised servers provide attackers with a direct path into the networks of all downstream managed clients. N-able’s initial patch was insufficient; build 2026.3.1.7, released 2 August, is the first fully remediated version.
Security Architect’s Take: If you run N-central, upgrade to build 2026.3.1.7 immediately and treat any server running an earlier build as potentially compromised — initiate incident response, review admin account activity, and audit downstream managed endpoints for lateral movement or persistence mechanisms.
Original advisory: N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete