TechNewsReel
Live

N-able N-central Auth Bypass Grants Attackers 'God-Mode' Access to Managed Endpoints

A flawed patch for a previous vulnerability allowed attackers to seize administrative control of RMM servers and pivot into customer environments.

TechNewsReel Newsroom · August 3, 2026

Attackers have exploited a critical authentication bypass vulnerability in N-able's N-central Remote Monitoring and Management (RMM) platform to gain remote administrative access to servers. The flaw, tracked as CVE-2026-18577, allowed unauthorized actors to seize full control of the management infrastructure, creating a high-risk pathway into the networks of managed clients.

According to N-able, the vulnerability affected N-central servers running versions prior to 2026.3.1.7. The breach resulted from an incomplete fix for a previous vulnerability, CVE-2026-18556. N-able stated that as their investigation continued, they "identified an alternative method to exploit this vulnerability, which was not mitigated in our previous fix."

Once administrative access to the N-central server was achieved, attackers utilized the platform's built-in 'Take Control' feature. This allowed them to pivot from the central management server directly into managed customer systems. To ensure long-term access, the attackers maintained persistence on compromised endpoints by registering a new service for a CloudFlare tunnel. N-able has identified several malicious IP addresses associated with the activity, including 173.249.252.200, 87.249.138.34, and 37.19.210.32.

The RMM Supply Chain Risk

N-central is widely used by Managed Service Providers (MSPs) to oversee large fleets of client devices. Because RMM tools are designed to possess high-level administrative privileges across diverse customer environments, they are primary targets for supply-chain style attacks. When a single management server is compromised, the trust relationship between the MSP and the client is weaponized, turning a security tool into a delivery mechanism for malware.

Implications of Incomplete Patching

This incident underscores the severe danger of "incomplete patches," where a vendor believes a security flaw is closed, but a secondary exploitation vector remains open. In this case, the failure to fully remediate the initial flaw effectively granted attackers "god-mode" access to every endpoint managed by the affected MSP. Such access provides a blueprint for widespread ransomware deployment or systemic data theft across multiple organizations simultaneously.

Next Steps for Administrators

Organizations using N-central must verify they are running version 2026.3.1.7 or later to mitigate the bypass. Security teams are advised to audit their endpoints for unauthorized services, specifically looking for unexpected CloudFlare tunnel registrations that may indicate a persistent breach. The industry continues to monitor for further indicators of compromise as the full scope of the pivot from RMM servers to client endpoints is analyzed.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.