Cyber Resilience
← All news
Corroborated

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

Our takeN-able's first patch for the N-central auth bypass (CVE-2026-18577) was incomplete; attackers used it to take over servers and reach customer systems. Update to 2026.3.1.7 or later.
Sources (2)
What this means for you — Security leader:N-able released build 2026.3.1.7 on August 2 to fully close CVE-2026-18577 after the first patch was bypassed in the wild. Immediately update all N-central servers and review logs for unauthorized administrative access.
What this means for you — Lean IT orgs:If you use N-central for monitoring or remote management, make sure it is running build 2026.3.1.7 or newer. Contact your provider today and ask them to confirm the version and whether they have checked for signs of compromise.
What this means for you — MSP:N-able's first patch for CVE-2026-18577 was incomplete and attackers have used it to take remote admin control of N-central servers and reach customer environments. Confirm every managed N-central instance is on build 2026.3.1.7, review for post-August-1 anomalous admin activity, and treat affected servers as breached.
What this means for you — Researcher:N-able disclosed active exploitation of authentication bypass CVE-2026-18577 in N-central; the initial fix was bypassed and the complete patch (build 2026.3.1.7) shipped August 2.