N-able N-central auth-bypass flaw is under active exploitation; customers told to verify 2026.3.1.7
N-able’s N-central RMM platform is under active exploitation through an authentication-bypass flaw, with Huntress reporting multiple affected organizations and observed follow-on activity including reconnaissance, process-list requests, and abuse of the Take Control remote-access feature on downstream hosts. N-central is a remote monitoring and management platform used to administer and remotely access systems across customer environments.
Huntress, CRN, and BleepingComputer reported that N-able released N-central 2026.3.1.7, also described as 2026.3 Hotfix 1, and urged customers to upgrade immediately. Later reporting indicates that stopping at the base 2026.3 release was not sufficient after expanded guidance.
Because N-central can execute scripts, jobs, software deployments, and remote-control sessions across managed environments, defenders should verify the actual deployed build, review administrator and configuration changes, and examine Take Control, server, identity, network, and endpoint logs for activity that predates remediation. The supplied reporting tracks the flaw as CVE-2026-18577, while sources disagree on a related earlier identifier.
Sources
- Huntress: Critical N-able N-central Vulnerability and Active Exploitation
- CRN: N-able N-central Flaw Sees Exploitation: 5 Things To Know
- BleepingComputer: N-able warns of N-central auth bypass flaw exploited in attacks
- The Futurum Group: N-able's Security Vulnerability Exposes Critical Risks for Legacy Systems