N-able Rushes Out Fix After Hackers Bypass Patch for N-central Servers
N-able has released a new patch for its N-central remote monitoring and management software after discovering that a previously issued fix for a security flaw, tracked as CVE-2026-18577, could be bypassed by attackers. The vulnerability has already been exploited in the wild to compromise N-central servers.
N-central is widely used by managed service providers (MSPs) to remotely monitor and manage IT systems for their clients, including many small and medium businesses. This makes vulnerabilities in the platform particularly concerning, as a successful attack on an MSP's N-central server could potentially give threat actors a foothold into the networks of multiple downstream businesses that rely on that MSP.
Businesses that use an MSP for IT support should check with their provider to confirm whether they use N-central and, if so, whether the latest patch has been applied. Given that this flaw has already been used in real-world attacks, prompt action is important to reduce the risk of compromise.