All stories
highExploited VulnerabilitiesCVE-2026-18577

Attackers can hijack N-central accounts through an authentication bypass vulnerability

N-able has released an urgent hotfix for N-central to address a high-severity authentication bypass vulnerability. Attackers can potentially take over accounts in unpatched instances. Upgrade to version 2026.3.1 immediately if you are self-hosting.

Summary

A critical security flaw in N-able N-central, identified as CVE-2026-18577, allows for authentication bypass and subsequent account takeover. The vulnerability stems from an incomplete patch for a previous issue (CVE-2026-18556). N-able has released a hotfix to mitigate this risk, urging all partners to update their environments as soon as possible.

Technical details

The flaw, tracked as CVE-2026-18577, carries a CVSS score of 8.2. It affects N-central instances running versions through 2026.3. The vulnerability is tied to an incomplete patch for CVE-2026-18556, which creates a path for attackers to bypass authentication mechanisms and seize control of accounts within the platform.

While the specific technical mechanism of the bypass remains undisclosed in current documentation, N-able has confirmed that all instances not running version 2026.3.1 are vulnerable.

Affected products and fixed versions

The vulnerability impacts all N-central instances. The following table outlines the remediation path:

Product Vulnerable Versions Fixed Version
N-able N-central Through 2026.3 2026.3.1 (Hotfix)

For users on N-central hosted instances (NCOD), the upgrade will be applied automatically by N-able. Self-hosted users must manually download and install the update via the N-able support portal.

Detection opportunities

If you suspect an instance has been compromised, N-able recommends searching for specific indicators of activity on your devices:

  • File Check: Search user documents folders for a file named svchost.exe.
  • Service Check: Look for a registered service named Cloudflared.
  • Network Check: Review firewall logs for inbound connections from suspicious IP addresses.

If any of these indicators are found, contact N-able support and engage your internal security response team immediately.

Defender guidance

Immediate action is required for all self-hosted N-central administrators.

  1. Apply the Hotfix: Upgrade to build 2026.3.1.7 or higher immediately. If you are running legacy versions, follow the official upgrade path to reach a supported version before applying the hotfix.
  2. Agent Upgrades: While the hotfix protects the N-central server itself without requiring an agent update, you should still upgrade your agents once the server is patched to ensure all security fixes and features are active. Note that the Windows Agent installer has increased in size from 90 MB to 180 MB; plan for higher bandwidth consumption and stagger upgrades to manage network load.
  3. Verify MFA Capabilities: Ensure administrators can access "Reset MFA" and "Disable Two-Factor Authentication" options in the UI, as recent updates have restored these capabilities which were previously unavailable for MSP SSO users.

Sources

  1. https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
  2. https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm
  3. https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
  4. https://www.cve.org/CVERecord?id=CVE-2026-18556
Harith Dilshan

Harith Dilshan

- Offensive Security Engineer | Ethical Hacker | Penetration Tester -