FORSMILE
JA
セキュリティ2026/08/03

[URGENT] N-able N-central CVE-2026-18577: Urgent Update to Patched Version – Administrator Privileges Seized via Authentication Bypass, Attacks Actively Observed

An authentication bypass vulnerability (CVE-2026-18577) in N-able N-central has been reported, with active exploitation confirmed. Update immediately to the patched version 2026.3.1.7.

Back to Blog

An authentication bypass vulnerability (CVE-2026-18577) has been discovered in N-able's remote monitoring and management (RMM) solution, 'N-able N-central'. This vulnerability has been confirmed to be actively exploited in widespread attacks, leading the U.S. CISA (Cybersecurity and Infrastructure Security Agency) to add it to their Known Exploited Vulnerabilities (KEV) catalog and urge immediate action. Because administrator privileges for N-able N-central could be seized and managed endpoints compromised, all affected users must update to the patched version immediately.

Immediate Actions to Take

  • Urgently update N-able N-central to version 2026.3.1.7 hotfix.
  • Consider isolating your N-central environment until the update is complete, and thoroughly check for any signs of potential compromise.
  • Enforce multi-factor authentication (MFA) and regularly audit user account access permissions.
  • Monitor and review N-central servers and managed endpoints for suspicious logins, account changes, job or automation modifications, and Take Control session history.

Vulnerability Overview and Scope of Impact

CVE-2026-18577 is an authentication bypass vulnerability that arose due to an incomplete patch for a previously fixed vulnerability (CVE-2026-18556). Exploiting this flaw allows a remote attacker to bypass N-able N-central's authentication mechanism and gain administrator privileges. All N-central versions prior to 2026.3.1.7 are affected. A successful attack could grant the attacker 'God-mode' control over the N-central console, allowing them to push scripts, deploy tools, or initiate remote control sessions on managed servers and workstations, including critical systems like domain controllers.

⚠ CVE Score — 最高危険度 / CRITICAL
8.2CRITICALCVE-2026-18577

Specific Impact and Attack Scenarios

In attacks exploiting this vulnerability, attackers remotely gain administrator access to N-central servers. They then use the 'Take Control' feature to connect to systems within customer environments managed by N-central. Confirmed attacks have involved registering new CloudFlare tunnel services on compromised devices, enabling persistent access to the environment even after N-central server access was revoked. CISA notes that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses a significant risk to federal government agencies.

Impact by Major Distribution

While N-able N-central servers run on a custom distribution of AlmaLinux 9, this vulnerability stems from a flaw in the N-central application layer's authentication mechanism, not the OS kernel or OSS middleware itself. However, Huntress warns that EDR (Endpoint Detection and Response) software is often not deployed in AlmaLinux-based RMM appliance environments, which could delay attack detection after a system has been compromised via RMM.

Response Procedures and Verification Methods

N-able has released the N-central 2026.3.1.7 hotfix and strongly recommends that all customers upgrade to this version immediately. Even after updating, it is crucial to continue following security best practices such as regular patching, implementing multi-factor authentication, auditing user access, and monitoring for unusual activity. Enhance log analysis and network traffic monitoring to check for signs of compromise.

📦
Amazon で関連書籍・ツールを検索
cybersecurity server security tools
Amazonで探す →(アソシエイトリンク)

Reference Sources and Official Patch Information

Related articles