Cyber Resilience
← All news
Confirmed

HIGH ALERT: Active exploitation of remote monitoring and management platform within Australia

Our takeACSC reports active exploitation of N-able N-central CVE-2026-18556 and CVE-2026-18577 in Australia. If you run N-central, patch now. If an MSP manages you through it, ask them today when they patched — a compromised RMM means the attacker manages your fleet.
Sources (3)
What this means for you — Security leader:ACSC confirms active exploitation of N-able N-central vulnerabilities CVE-2026-18556 and CVE-2026-18577. Assess any RMM exposure and apply the published mitigations immediately.
What this means for you — Lean IT orgs:If you use N-able or N-central for remote monitoring, check for these two vulnerabilities right away and apply the fixes or workarounds listed in the ACSC alert.
What this means for you — MSP:ACSC reports active exploitation of N-able N-central (CVE-2026-18556, CVE-2026-18577) inside Australia. Review every client using this RMM platform and deploy the mitigations without delay.
What this means for you — Researcher:ACSC confirms in-the-wild exploitation of two N-able N-central flaws (CVE-2026-18556 and CVE-2026-18577). The advisory and linked mitigations are the primary source.