7 August 2026

3 min read

Cyber threat advisory: Active exploitation of N-able N-central

Cyber security
S-RM cyber threat advisory

Background

Since early August 2026, S-RM has responded to several ransomware incidents in which attackers have gained initial access through vulnerable N-able N-central servers. N-central is a remote monitoring and management platform used by managed service providers and internal IT teams to administer computer networks. This trusted access means that a compromise of one N-central server can give an attacker a route into multiple managed systems.

The vulnerability, tracked as CVE-2026-18577, is an authentication bypass caused by an incomplete patch for an earlier vulnerability, CVE-2026-18556. It can allow a remote attacker without valid credentials to obtain administrative control of a vulnerable N-central server. From there, the attacker may use legitimate management functions to access connected systems.

N-able released Hotfix 1, build 2026.3.1.7, on 2 August 2026, which addressed the earlier vulnerability. On 6 August, it released Hotfix 2, build 2026.3.1.10, which supersedes the earlier update and adds further protections to mitigate the latest vulnerability.

Organisations operating self-hosted N-central environments should upgrade to 2026.3.1.10 immediately, even if Hotfix 1 has already been installed. N-able states that mitigations have already been applied to N-able-hosted environments.

Affected systems

All self-hosted N-central environments running build 2026.3.1.7 or lower should be treated as vulnerable and require an urgent update. Only build 2026.3.1.10 should be considered secure.

Indicators of compromise

S-RM's Incident Response team has observed the following indicators of compromise and tactics, techniques and procedures (TTPs) in incidents where attackers have gained initial access through N-central:

  • Using N-central’s legitimate Take Control feature to access critical servers and other managed devices.
  • Executing Advanced IP Scanner to identify systems and services on the network.
  • Installing additional remote access solutions, including Anydesk, Tactical RMM, Simple Help, and EMCO.
  • Creating new accounts and adding them to the Active Directory Domain Administrators group, giving them extensive control over the network and domain.
  • Establishing Cloudflare tunnels for persistent remote access, including through an executable named conhost.exe that was in fact a renamed copy of the legitimate Cloudflare tunnelling tool.
  • Using Rclone to exfiltrate data from the network.
  • Using a vulnerable driver, bootrepair.sys (also observed as p.sys) associated with Phantom Killer to disable or bypass endpoint security tooling.
  • Deploying ransomware to encrypt data.

What to do now

We urgently advise organisations using N-central to take the following steps:

    • Update immediately: Upgrade self-hosted N-central servers with the latest Hotfix 2, build 2026.3.1.10. This update is required even if Hotfix 1 was installed.
    • Confirm hosted protection: N-able states that mitigations have already been applied to N-able-hosted N-central environments. Confirm the status of your instance through your normal vendor support channel.
    • Reset credentials: Rotate administrative and service-account credentials associated with N-central. In addition, review privileged accounts and ensure all are legitimate and enforce multi-factor authentication wherever possible.
    • Hunt for compromise: Review N-central and endpoint activity for unauthorised remote-control session, unexpected accounts or services, suspicious tools, data transfers and lateral movement. Do not assume that applying the update removes access that may already have been established elsewhere in the environment.
    • Preserve relevant logs: Retain N-central, endpoint, identity, firewall and remote-access records to support investigation if suspicious activity is identified.

If malicious activity is identified

  1. Isolate N-central: Restrict or disable external access to the affected N-central server and contain compromised systems, while avoiding changes that could destroy valuable evidence.
  2. Activate your incident response plan: Engage appropriate incident response support vendors for assistance where necessary.
  3. Preserve evidence: Secure relevant logs, system images, and configuration data before rebuilding or removing tools.
  4. Contain the broader environment: Investigate managed endpoints for persistent access, newly created accounts, remote management tools, Cloudflare tunnels, credential abuse, data theft, and ransomware activity.
  5. Engage specialist support: An experienced cyber incident response provider can help determine the scope of the compromise, remove the threat actor’s access, and support a secure recovery.

Please contact S-RM if you are concerned that your organisation may be exposed or if you identify signs of suspicious activity.

Subscribe to our insights

Get industry news and expert insights straight to your inbox.