CVE-2026-18577: N-able N-central Auth Bypass Exploited as Zero Day for Domain Compromise

Share:

N-able has patched an actively exploited flaw in N-central, a platform that IT teams and managed
service providers use to remotely monitor and manage large fleets of computers. The flaw, CVE-2026
18577, lets an attacker bypass the login and gain privileged control of the N-central console, and
attackers used it as a zero-day from 31 July 2026 to break into a customer’s network, take over domain
administrator accounts, and install remote-access tools on key servers. Any organisation running N
central should apply the 2026.3.1.7 hotfix at once and check for signs of compromise.

1. Vulnerability Details

CVE ID – CVE-2026-18577
EXPLOIT STATUS – Active exploitation confirmed. N-able states exploitation began on 31 July 2026 as a zero-day. A hotfix, version 2026.3.1.7, shipped on 2 August 2026. Sophos found a single compromised
organisation and no evidence of widespread exploitation.

CVE-2026-18577 is an authentication bypass in N-able N-central that gives an unauthenticated attacker privileged access to the platform’s management interface, in both hosted and on-premises deployments. Because N-central manages large fleets of endpoints, that console access converts directly into remote control of every managed device.
The flaw was reported to stem from an incomplete fix for the earlier CVE-2026-18556, though N-able has not confirmed this. N-able disclosed active exploitation on 1 August 2026 and released the 2026.3.1.7 hotfix on 2 August; there is no workaround.

2. Affected Products

  • N-able N-central, all versions prior to 2026.3, in both hosted and on-premises deployments.
  • Fixed in the 2026.3.1.7 hotfix. Hosted instances received mitigations first, with the hotfix rollout following; on-premises customers must upgrade manually.
  • Upgrading to 2026.3.1 also addresses the related CVE-2026-18556.

3. Exploitation and Intrusion

N-able disclosed active exploitation on 1 August 2026 and later confirmed it began on 31 July as a zero-day. SophosCTU found a single compromised organisation in its telemetry and no evidence of widespread compromise.

  • Initial compromise: On 3 August 2026 at about 08:00 UTC, the actor exploited an internet-reachable N-central server and used its remote-control capability to reach a backup server, domain controllers, and application servers.
  • Domain takeover: The actor created a new domain account named veeam, reset several domain administrator passwords, and enumerated accounts and domain controllers with net user, nltest /dclist:, and net group “domain admins” /domain.
  • EDR evasion The actor ran tasklist piped to findstr ms and findstr soph to find Microsoft Defender and Sophos hosts, then used the PhantomKiller tool, seen as 9.exe, to load a k.sys driver from C:\ProgramData\AnyDesk and terminate sophosfilescanner.exe.

4. Other Notable CVEs

  • CVE-2026-18556 (CVSS Not published) Earlier N-central flaw whose incomplete fix is reported, but not confirmed by N-able, as the underlying cause of CVE-2026-18577. Also addressed by upgrading to 2026.3.1.

5. Adversary Toolkit

ToolLanguage / TypeFunction
PhantomKillerEDR evasion tool (9.exe)Loads a k.sys driver from C:\ProgramData\AnyDesk to disable or terminate security products such as Sophos File Scanner.
Cloudflare Tunnelcloudflared.exe (renamed)Legitimate tunnel renamed to MicrosoftEdgeUpdate64.exe or msmp.exe to masquerade as a benign process and provide persistent remote access.
TacticalRMMinstall_server.ps1 / tacticalagentOpen-source Remote Monitoring and Management (RMM) tool deployed to endpoints for remote command execution and control.
AnyDesk, TeamViewer, RustDesk, SimpleHelp, HopToDeskLegitimate RMM toolsMultiple remote-access tools deployed across endpoints to broaden and maintain the threat actor’s control.

6. Indicators of Compromise (IOCs)

TYPE INDICATOR

IP – 173[.]249[.]252[.]200

IP – 172[.]249[.]252[.]176

IP – 87[.]249[.]138[.]34

IP – 37[.]19[.]210[.]32

IP – 68[.]235[.]46[.]214

IP – 68[.]235[.]46[.]235

IP – 37[.]153[.]90[.]88

IP – 92[.]118[.]112[.]181

IP – 23[.]234[.]94[.]43

IP – 185[.]156[.]46[.]150

DOMAIN – who-ripped-one[.]direct[.]quickconnect[.]to

DOMAIN – mousears[.]synology[.]me

DOMAIN – wagoosh[.]direct[.]quickconnect[.]to

DOMAIN – api[.]mendoratech[.]health

7. Recommendations

  • Upgrade every N-able N-central instance, hosted and on-premises, to the 2026.3.1.7 hotfix immediately; all versions before 2026.3 are affected and there is no workaround.
  • Treat internet-reachable N-central servers as potentially compromised and hunt for the intrusion markers: a new veeam domain account, reset domain-admin passwords, and renamed cloudflared.exe (MicrosoftEdgeUpdate64.exe, msmp.exe).
  • Remove the attacker’s RMM tools and tunnels (AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, HopToDesk, Cloudflare Tunnel) and the PhantomKiller driver k.sys from C:\ProgramData\AnyDesk on affected endpoints.
  • Reset all domain administrator passwords, remove unauthorised accounts such as veeam, and rotate
  • credentials on the N-central server and every endpoint it reached, including backup servers and domain controllers.
  • Block the IOCs at their respective controls.

8. Sources

  • https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment
  • https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-1857
    7/
  • https://www.cve.org/CVERecord?id=CVE-2026-18577

Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn

No related posts found.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert