On August 1, 2026, N-able released an advisory for CVE-2026-18556, affecting version 2026.1 of their RMM platform, N-central. This vulnerability was described by N-able as an “unauthenticated administrative account takeover” and listed all versions through 2026.1 as vulnerable, and that released versions 2026.2 and 2026.3 had already been patched.
After the initial post, N-able recognized the possibility of exploitation on updated versions and later released a supporting advisory for CVE-2026-18577 as a closely related vulnerability through a different path.
All N-central customers should update to the latest version 2026.3.1.7, which N-able claims to resolve the vulnerability.
Attackers exploit authentication bypass to gain remote administrative access
CVE-2026-18556 is an authentication bypass vulnerability affecting N-central servers.
Both on-prem and cloud-hosted installations are vulnerable, granting attackers administrative access capabilities such as remote access sessions to managed devices through N-able Take Control, script execution, and job automation.
In addition, attackers have the ability to change configurations such as users, roles, and policies, and they can potentially affect downstream customers through compromised networks. Technical information on the exploitation of this CVE has not been released, but the disclosure clearly states the wide impact and devastating effects present.
N-central version 2026.2 was released on April 28, 2026, and considered by N-able as the fix for CVE-2026-18556. Version 2026.2 was released with no mention of CVE-2026-18556, and no publicly available third-party research or verification was performed ensuring the vulnerability was sufficiently fixed.
On July 31, 2026, N-able saw a significant increase in licensing issues from N-central customers. Investigation into these issues revealed that the previously patched exploit was still available through a different vector. Upon discovery, a second CVE was released on August 2, 2026: CVE-2026-18577.
Exploitation of CVE-2026-18556 and CVE-2026-18577 led to malicious persistence being established on managed devices. User Documents folders were populated with an svchost.exe binary and malicious services were registered under the name Cloudflared. Several IP addresses are provided below that were observed leveraging these CVEs for unauthorized access.
Conclusion
Based on the published CVEs and disclosures by N-able, affected clients should upgrade to the latest version of N-central 2026.3.1.7 to address vulnerable instances of N-central.
Although N-able has stated that the latest version of N-central is fixed, technical information regarding the exploit and its patch still has not been disclosed, and the safety of client environments is left to the discretion of N-able.
Mitigations
Publicly accessible installations of N-central should be removed from public internet access until patching is complete. Since this vulnerability does not require authentication, applying security measures such as MFA would be ineffective to prevent unwanted access.
Once unauthorized access is made impossible, N-central servers should be updated to prevent further exploitation.
- Upgrade every instance of N-central server to build
2026.3.1.7immediately - If patching options are limited or unavailable, take unpatched N-central servers offline until patching options are available
- Remove or heavily restrict access to direct public exposure of N-central consoles
- Review N-central administrative accounts and privileges
- If suspicious activity is present, revoke access to potentially compromised accounts
- Audit logs for suspicious remote access activity, scripts, and jobs
- Hunt for services named
Cloudflaredand binarysvchost.exe - Review network infrastructure logs for network activity to the IP addresses listed in the IOC section
IOCs
IPs
- 173[.]249[.]252[.]200
- 87[.]249[.]138[.]34
- 37[.]19[.]210[.]32
- 37[.]153[.]90[.]88
- 92[.]118[.]112[.]181
- 68[.]235[.]46[.]214
Artifacts
svchost.exelocated inDocumentsfolder
Services
Cloudflared


