N-able N-central (versions prior to 2026.3.1.7)
N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) — companies that handle IT infrastructure for other businesses — to monitor, patch, and remotely access their clients' servers and devices.
Root Cause
This is a bypass of a previously patched flaw (CVE-2026-18556). Attackers found a new path around the fix and began exploiting it in late July 2026. The authentication layer failed to close all routes into privileged account access.
Attack Vector
An attacker with network access sends a crafted request to the N-central console, bypasses authentication, and gains full admin control. From there, they can deploy scripts to managed endpoints, run remote sessions on critical servers, and register Cloudflare tunnels (persistent encrypted channels that survive even after server access is revoked) to maintain a foothold.
Detection Notes
Check N-central audit logs for admin account creation or logins from unrecognised IP addresses. Look for new Cloudflare tunnel registrations or unfamiliar services appearing on managed endpoints. Monitor for unexpected script deployments pushed through the N-central agent.
Recommended Actions
- Upgrade to N-central version 2026.3.1.7 immediately.
- Review indicators of compromise published by N-able and Huntress.
- Audit admin accounts and active Cloudflare tunnels across your N-central environment.

