N-able's patch for a critical N-central flaw left a second hole attackers are now using to hijack MSP servers

N-able has confirmed that attackers are actively exploiting its N-central remote monitoring and management platform, even after the company shipped a patch for the original vulnerability. The incomplete fix left a second exploitation path open, and researchers say attackers are now using it to hijack servers used by managed service providers to administer customer IT systems.
A patch that didn't finish the job
The original flaw, tracked as CVE-2026-18556, is an unauthenticated administrative account takeover — attackers could gain full administrative access to an N-central server without valid credentials. N-able released build 2026.2 to close that hole. But researchers subsequently found an alternate route into the same class of bug, cataloged as CVE-2026-18577, which affects all builds prior to 2026.3.1.7, released just one day before this disclosure on August 2.
That gap between the first patch and the actual fix is what attackers exploited. N-central is widely deployed by managed service providers (MSPs) — companies that remotely administer IT infrastructure for dozens or hundreds of downstream client organizations from a single console. Compromising one N-central instance can open a path into every business that MSP manages, which is exactly what makes remote-management software a high-value target.
How the attack unfolds
Once attackers gain administrative access to a vulnerable N-central server, they use its built-in “Take Control” feature — designed for legitimate remote support — to reach managed endpoints. From there, they register Cloudflare tunnels as persistent services on those endpoints. Because Cloudflare tunnels connect outbound to Cloudflare's edge network, they require no inbound firewall rule and no open listening port, making them difficult to detect with conventional network monitoring. Running the tunnel as a system service also means it survives a reboot, giving attackers durable, low-visibility access.
Scope and real-world impact
N-able has acknowledged a “limited number of affected customers” but has not disclosed exact figures. Security firm Huntress, which investigates incidents across the MSP ecosystem, reported observing active exploitation at one organization that cascaded down to nine separate downstream companies, with attackers reaching at least one endpoint in each — a concrete illustration of how a single compromised management platform can ripple outward through an entire client base.
What administrators need to do now
N-able is urging all N-central customers to upgrade immediately to build 2026.3.1.7 or later. Beyond patching, administrators should audit logs for unauthorized “Take Control” sessions, hunt for unfamiliar Cloudflare tunnel services running on managed endpoints, and watch for suspicious svchost.exe processes launching from user Documents folders — a pattern investigators have tied to this specific attack chain.
As reported by The Hacker News, this incident underscores a recurring problem in the MSP software category: remote-management tools are built for broad, privileged access by design, which makes any authentication gap in them disproportionately dangerous compared to a flaw in a single standalone application.
Originally reported by The Hacker News. Read the original article for additional details.
View original source