
N-able has confirmed that attackers exploited two vulnerabilities in its N-central platform to remotely gain administrative access to on-premises servers running version 2026.1 and earlier. N-central is the remote monitoring and management (RMM) platform that managed service providers and IT teams use to remotely administer their clients’ endpoint devices — making it an attractive target because a compromised N-central server can serve as a bridge to hundreds or thousands of downstream business machines. N-able discovered the intrusion on July 31, 2026, after noticing an unusual volume of licensing errors from on-premises customers, and identified a limited number of affected organizations.
The two vulnerabilities, CVE-2026-18556 and CVE-2026-18577, are each scored 8.2 under CVSS 4.0. N-able’s initial fix proved incomplete; attackers were able to maintain access through Cloudflare tunnel services installed on managed endpoints, which survived even after the server-side route was revoked. Build 2026.3.1.7, released August 2, 2026, is the first fully unaffected version. Security firm Huntress investigated the incident and found that the confirmed exploitation was contained to nine organizations reached through a single compromised MSP partner account. In those cases, attacker activity appeared limited to enumerating running processes before disconnecting — but N-able has not confirmed whether data was taken or whether the full scope of affected customers has been identified. Six IP addresses used in the attacks have been published by N-able; Huntress identified four of them as Mullvad or NordVPN exit nodes.
How to check if you’re affected
Affected versions are N-central builds prior to 2026.3.1.7. If you operate an on-premises N-central server, upgrade to build 2026.3.1.7 immediately. Upgrading the server does not remove persistence already installed on managed endpoints — Huntress recommends also checking managed Windows endpoints for svchost.exe in users’ Documents folders, a service named Cloudflared, or network traffic to the six IP addresses published by N-able. To detect unauthorized remote access sessions, review ui_access_control.log and correlate with C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz. Any sessions tied to mspsupport@n-able.com warrant investigation.
