TechNewsReel
Live

N-able confirms 'God Mode' flaw used to breach customer networks

A critical authentication bypass in the N-central RMM platform allowed unauthenticated actors to pivot from management servers into downstream client environments.

TechNewsReel Newsroom · August 7, 2026

N-able has confirmed that threat actors exploited a critical authentication bypass vulnerability in its N-central Remote Monitoring and Management (RMM) platform to gain full administrative access. The flaw, tracked as CVE-2026-18577, effectively granted attackers "god mode" control over management servers, enabling them to breach downstream customer networks.

According to N-able and security reports from The Register and ThreatLocker, the attackers utilized the platform's built-in "Take Control" feature to pivot from the compromised management server directly into managed endpoints. Once inside these customer environments, the threat actors established long-term persistence by registering Cloudflare Tunnel services on the compromised systems. The vulnerability was first identified on July 31, 2026, by N-able's Adlumin MDR service.

The RMM Supply Chain Risk

N-central is a centralized tool used by Managed Service Providers (MSPs) to monitor and administer vast arrays of client systems from a single interface. Because these platforms are designed to have deep, privileged access to hundreds of separate corporate networks, they are high-value targets for supply chain attacks. A single point of failure at the MSP level can potentially expose every single one of their clients to a simultaneous breach.

Industry Implications

This incident underscores the systemic risk inherent in the RMM ecosystem, where the tools used for security and maintenance can be weaponized to provide wide-scale access to protected environments. The speed and method of the attack—moving from a server to an endpoint and immediately deploying a tunnel for persistence—demonstrate a sophisticated approach to maintaining access even after initial detection.

Remediation and Next Steps

N-able has issued a second mandatory hotfix, version 2026.3.1.10, for on-premises customers. The company explicitly stated that "Hotfix 2 is required, even if you already applied the earlier hotfix," suggesting that initial mitigation efforts may have been insufficient to fully close the vulnerability. Organizations using N-central are urged to verify their versioning and audit their endpoints for unauthorized Cloudflare Tunnel installations. It remains to be seen how many total customer environments were accessed before the flaw was fully patched.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.