CISA Adds Exploited N-able N-central Auth Bypass to KEV Catalog
A high-severity flaw allowing full account takeover was exploited to compromise managed endpoints via Cloudflare tunnels.
The Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog. The flaw, tracked as CVE-2026-18577, allows remote attackers to bypass authentication and achieve full takeover of administrator accounts.
According to the National Vulnerability Database (NVD), CVE-2026-18577 carries a CVSS score of 8.2. The vulnerability emerged as an incomplete patch for a previous flaw, CVE-2026-18556. While N-able addressed the earlier issue in version 2026.2, security researchers discovered an alternate path that left systems exposed. N-able has since released a fix in version 2026.3.1.7 (2026.3 Hotfix 1).
The RMM Attack Vector
N-able N-central is a Remote Monitoring and Management (RMM) tool used extensively by Managed Service Providers (MSPs) to oversee client endpoints. Because RMMs provide high-level administrative access to a vast array of downstream systems, they are primary targets for supply-chain attacks. In this instance, the failure of an initial security patch created a window of exposure that threat actors exploited to gain a foothold in MSP environments.
Impact and Persistence
Once attackers gained administrator access to the N-central server, they utilized the legitimate 'Take Control' feature to pivot directly to managed endpoints. This allowed them to bypass traditional perimeter defenses and reach critical infrastructure, including domain controllers.
To maintain access, attackers established persistence on these endpoints by registering a new service for a Cloudflare tunnel. N-able confirmed that this method enabled attackers to maintain a connection to the environment even after their access to the primary N-central server was revoked. Technical indicators of this persistence include a file named 'svchost.exe' located in the Documents folder and a registered service named 'Cloudflared'.
Industry Implications
As Huntress analysts noted, a compromised RMM can act as a "force multiplier" against every downstream client managed by a provider. The ability to use legitimate administrative tools for malicious movement makes detection exceptionally difficult for the end client, as the traffic appears to originate from a trusted management source. For MSPs, a single vulnerability in their management stack can lead to the simultaneous compromise of dozens or hundreds of separate organizations.
Next Steps for Administrators
Organizations using N-able N-central are urged to update to version 2026.3.1.7 immediately. Security teams should also audit their managed endpoints for the specific indicators of compromise mentioned by N-able, specifically searching for unauthorized Cloudflare tunnel services and suspicious executables in user document directories.