TechNewsReel
Live

N-able issues second mandatory hotfix as attackers breach managed networks

A critical authentication bypass in the N-central RMM platform allowed threat actors to gain administrative control and infiltrate downstream client systems.

TechNewsReel Newsroom · August 8, 2026

N-able has released a second mandatory hotfix for its N-central Remote Monitoring and Management (RMM) platform following the active exploitation of a critical zero-day vulnerability. The flaw allowed unauthenticated attackers to seize full administrative control of management servers, providing a direct gateway into the networks of managed customers.

The vulnerability, tracked as CVE-2026-18577, granted attackers what is described as "god-mode" access to the N-central console. Once inside the management server, threat actors utilized the platform's legitimate "Take Control" feature to move laterally from the server to managed endpoints. To ensure they maintained a foothold on these downstream systems, attackers registered Cloudflare Tunnel services, allowing them to persist even if their access to the primary N-central server was revoked. In response, N-able deployed hotfix version 2026.3.1.10 for on-premises customers.

The RMM Supply Chain Risk

N-central is designed to allow Managed Service Providers (MSPs) to administer vast numbers of client systems from a single, centralized point of control. While this efficiency is a core value for service providers, it creates a significant security bottleneck. Because the platform possesses high-level privileges across all connected environments, a single compromise at the provider level can trigger a massive supply-chain style breach, exposing hundreds of downstream organizations simultaneously.

Industry Implications

This incident underscores the systemic risk inherent in the RMM ecosystem, where the tools used for security and maintenance can be weaponized into delivery mechanisms for malware or data exfiltration. The necessity of a second mandatory hotfix shortly after the first suggests that threat actors were rapidly evolving their techniques to bypass initial mitigations. N-able stated that it is "proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques."

What to Watch

Security teams and MSPs are now tasked with auditing managed endpoints for unauthorized Cloudflare Tunnel services, which served as the primary persistence mechanism in this campaign. While the hotfix addresses the initial authentication bypass, the presence of these tunnels indicates that the breach may have extended beyond the management console. Organizations should monitor for unusual outbound traffic and verify the integrity of administrative accounts across their managed infrastructure.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.