N-able has patched an actively exploited flaw in N-central, a platform that IT teams and managed
service providers use to remotely monitor and manage large fleets of computers. The flaw, CVE-2026
18577, lets an attacker bypass the login and gain privileged control of the N-central console, and
attackers used it as a zero-day from 31 July 2026 to break into a customer’s network, take over domain
administrator accounts, and install remote-access tools on key servers. Any organisation running N
central should apply the 2026.3.1.7 hotfix at once and check for signs of compromise.
1. Vulnerability Details
CVE ID – CVE-2026-18577
EXPLOIT STATUS – Active exploitation confirmed. N-able states exploitation began on 31 July 2026 as a zero-day. A hotfix, version 2026.3.1.7, shipped on 2 August 2026. Sophos found a single compromised
organisation and no evidence of widespread exploitation.
CVE-2026-18577 is an authentication bypass in N-able N-central that gives an unauthenticated attacker privileged access to the platform’s management interface, in both hosted and on-premises deployments. Because N-central manages large fleets of endpoints, that console access converts directly into remote control of every managed device.
The flaw was reported to stem from an incomplete fix for the earlier CVE-2026-18556, though N-able has not confirmed this. N-able disclosed active exploitation on 1 August 2026 and released the 2026.3.1.7 hotfix on 2 August; there is no workaround.
2. Affected Products
- N-able N-central, all versions prior to 2026.3, in both hosted and on-premises deployments.
- Fixed in the 2026.3.1.7 hotfix. Hosted instances received mitigations first, with the hotfix rollout following; on-premises customers must upgrade manually.
- Upgrading to 2026.3.1 also addresses the related CVE-2026-18556.
3. Exploitation and Intrusion
N-able disclosed active exploitation on 1 August 2026 and later confirmed it began on 31 July as a zero-day. SophosCTU found a single compromised organisation in its telemetry and no evidence of widespread compromise.
- Initial compromise: On 3 August 2026 at about 08:00 UTC, the actor exploited an internet-reachable N-central server and used its remote-control capability to reach a backup server, domain controllers, and application servers.
- Domain takeover: The actor created a new domain account named veeam, reset several domain administrator passwords, and enumerated accounts and domain controllers with net user, nltest /dclist:, and net group “domain admins” /domain.
- EDR evasion The actor ran tasklist piped to findstr ms and findstr soph to find Microsoft Defender and Sophos hosts, then used the PhantomKiller tool, seen as 9.exe, to load a k.sys driver from C:\ProgramData\AnyDesk and terminate sophosfilescanner.exe.
4. Other Notable CVEs
- CVE-2026-18556 (CVSS Not published) Earlier N-central flaw whose incomplete fix is reported, but not confirmed by N-able, as the underlying cause of CVE-2026-18577. Also addressed by upgrading to 2026.3.1.
5. Adversary Toolkit
| Tool | Language / Type | Function |
| PhantomKiller | EDR evasion tool (9.exe) | Loads a k.sys driver from C:\ProgramData\AnyDesk to disable or terminate security products such as Sophos File Scanner. |
| Cloudflare Tunnel | cloudflared.exe (renamed) | Legitimate tunnel renamed to MicrosoftEdgeUpdate64.exe or msmp.exe to masquerade as a benign process and provide persistent remote access. |
| TacticalRMM | install_server.ps1 / tacticalagent | Open-source Remote Monitoring and Management (RMM) tool deployed to endpoints for remote command execution and control. |
| AnyDesk, TeamViewer, RustDesk, SimpleHelp, HopToDesk | Legitimate RMM tools | Multiple remote-access tools deployed across endpoints to broaden and maintain the threat actor’s control. |
6. Indicators of Compromise (IOCs)
TYPE INDICATOR
IP – 173[.]249[.]252[.]200
IP – 172[.]249[.]252[.]176
IP – 87[.]249[.]138[.]34
IP – 37[.]19[.]210[.]32
IP – 68[.]235[.]46[.]214
IP – 68[.]235[.]46[.]235
IP – 37[.]153[.]90[.]88
IP – 92[.]118[.]112[.]181
IP – 23[.]234[.]94[.]43
IP – 185[.]156[.]46[.]150
DOMAIN – who-ripped-one[.]direct[.]quickconnect[.]to
DOMAIN – mousears[.]synology[.]me
DOMAIN – wagoosh[.]direct[.]quickconnect[.]to
DOMAIN – api[.]mendoratech[.]health
7. Recommendations
- Upgrade every N-able N-central instance, hosted and on-premises, to the 2026.3.1.7 hotfix immediately; all versions before 2026.3 are affected and there is no workaround.
- Treat internet-reachable N-central servers as potentially compromised and hunt for the intrusion markers: a new veeam domain account, reset domain-admin passwords, and renamed cloudflared.exe (MicrosoftEdgeUpdate64.exe, msmp.exe).
- Remove the attacker’s RMM tools and tunnels (AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, HopToDesk, Cloudflare Tunnel) and the PhantomKiller driver k.sys from C:\ProgramData\AnyDesk on affected endpoints.
- Reset all domain administrator passwords, remove unauthorised accounts such as veeam, and rotate
- credentials on the N-central server and every endpoint it reached, including backup servers and domain controllers.
- Block the IOCs at their respective controls.
8. Sources
- https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment
- https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-1857
7/ - https://www.cve.org/CVERecord?id=CVE-2026-18577
Enjoyed reading this Threat Intelligence Advisory? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn
No related posts found.