N-able warns of N-central auth bypass flaw exploited in attacks
N-able has issued a warning after confirming that cybercriminals are actively exploiting an authentication bypass vulnerability in N-central, its widely used remote monitoring and management platform. The flaw, tracked as CVE-2026-18577, impacts all versions prior to 2026.3.1.7 and can allow unauthorized access to sensitive systems managed through the tool. A hotfix was released on August 2nd to resolve the issue, and users of on-premises deployments are urged to apply it manually. Hosted versions have already been updated. The vulnerability stems from an incomplete fix for another related flaw, CVE-2026-18576, which also allowed bypassing authentication mechanisms. While no specific details about the scale of exploitation were provided, the company shared indicators of compromise on its status page, including suspicious IP addresses and activity involving Cloudflared. Customers are encouraged to review these indicators and reach out to N-able support if anomalies are detected.