CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

N-able N-central Authentication Bypass Exploited: Attackers Take Over Servers, Abuse Cloudflare Tunnels

August 3, 2026

N-able has disclosed that attackers exploited an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) platform, gaining remote administrative access to servers and reaching managed customer endpoints. The initial fix for the flaw proved incomplete, prompting the company to release an emergency hotfix.

The vulnerabilities, tracked as CVE-2026-18556 and CVE-2026-18577, are both classified as authentication bypasses (CWE-288) and carry a CVSS score of 8.2. CVE-2026-18556 affects releases through 2026.1, while CVE-2026-18577 expands the affected range to builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.

After compromising N-central servers, attackers used the Take Control feature to reach managed endpoints and installed Cloudflare tunnels as services on those devices. These tunnels connect outbound to Cloudflare’s edge, requiring no inbound firewall rules or open ports, and running as services allows them to survive reboots. N-able noted that the tunnels preserved access even after the route through the N-central server was revoked. There is no indication that Cloudflare itself was compromised.

N-able began investigating on July 31 after observing an unusual volume of licensing errors from on-premises customers. The company identified and contacted a limited number of affected customers but did not disclose the exact count. Finland’s national cyber security centre issued an advisory on August 2 stating that all versions before the emergency hotfix were vulnerable.

N-able has published six IP addresses associated with the attacks and advised customers to look for indicators such as svchost.exe in users’ Documents folders, a service named Cloudflared, or traffic from the listed IPs. Huntress, a security firm, reported seeing exploitation at one organization in its customer base and identified three attacker domains. Huntress noted that the post-compromise activity was limited to enumerating running processes before the attackers disconnected, and it did not observe the Cloudflare installation activity described by N-able.

N-able has not disclosed the number or identities of affected customers, how many downstream devices were reached, when exploitation began, who is behind it, or whether any data was taken. Customers are urged to upgrade to build 2026.3.1.7 immediately and to hunt for and remove any malicious tunnel services from managed endpoints, as upgrading N-central alone does not remove persistence installed on other machines.

CVEs: CVE-2026-18556, CVE-2026-18577, CVE-2026-50522

Companies: N-able, Huntress, Cloudflare, Mullvad, NordVPN

Products: N-central, Take Control