Urgent: New Bypass Flaw Found in N-able RMM Software Gives Attackers Admin Access
N-able, a widely used remote monitoring and management (RMM) platform relied on by managed service providers (MSPs) to oversee client IT systems, has disclosed a new security flaw tracked as CVE-2026-18577. According to the vendor, this vulnerability represents another way attackers can bypass authentication controls, effectively handing them administrator access to affected servers without needing valid credentials.
Because RMM tools like N-able are used by MSPs to manage multiple client networks at once, a successful attack against a single N-able server can potentially expose many downstream businesses to compromise. Attackers gaining administrator access through this flaw could use that foothold to deploy malware, steal data, or pivot into connected client environments. The vendor discovered this bypass over the weekend, indicating the issue was identified in response to ongoing security review or active exploitation attempts.
Small businesses that rely on an MSP for IT support should not assume they are unaffected simply because they don't manage RMM software directly — if their provider uses N-able, they could be indirectly at risk until the flaw is patched and confirmed resolved.