N-able's first fix for an N-central auth bypass missed a second exploitation path
Attackers used an authentication bypass in N-able's N-central RMM platform to gain administrative access and register persistent Cloudflare tunnels on managed endpoints. N-able's initial patch blocked only one exploitation route; a second CVE covers the one it missed.
N-able disclosed two authentication bypass vulnerabilities in its N-central remote monitoring and management platform. CVE-2026-18556, an unauthenticated administrative account takeover affecting releases through 2026.1, was addressed in 2026.2, but researchers found an alternate way to exploit the same underlying flaw that the fix didn't block, tracked separately as CVE-2026-18577 and fully closed only in build 2026.3.1.7, released August 2. Both score 8.2 on CVSS 4.0. N-able began investigating on July 31 after detecting unusual licensing errors, and security firm Huntress published rapid-response findings on August 3. Attackers who reached administrative access used it to register Cloudflare tunnels as persistent services on managed endpoints, giving them continued access to customer environments even after the N-central server itself was remediated.
Why it matters
An RMM platform's authentication is the perimeter for every endpoint it manages, so an admin-level auth bypass here doesn't stay contained to one server, it's a foothold into every managed customer downstream. The incomplete first fix is the sharper lesson: closing one exploitation path for an authentication flaw isn't the same as closing the vulnerability class, and the Cloudflare tunnel persistence technique means remediating the N-central server alone won't evict an attacker who already got in.
If you run N-central, confirm you're on 2026.3.1.7 specifically, and hunt for unrecognized Cloudflare tunnel registrations on managed endpoints rather than trusting that the server-side patch alone closed the door.
Source: The Hacker News
Related on Start with Identity
- BlogN-able confirms attackers used an N-central auth bypass to reach managed customer networks
CVE-2026-18577 gave unauthenticated attackers full administrative control of N-central, which they used through the Take Control feature to reach downstream man
- BlogEvery on-premises TeamCity server is vulnerable to an auth bypass in the agent polling protocol
CVE-2026-63077 lets an unauthenticated attacker abuse TeamCity's agent polling protocol to bypass authentication and run arbitrary OS commands with the server p
- BlogQilin ransomware affiliates are using a patched PAN-OS auth bypass as their front door
Arctic Wolf Labs traced multiple June 2026 Qilin ransomware intrusions to a patched Palo Alto Networks PAN-OS flaw that lets attackers establish a VPN session w
- CVEN-able N-central auth bypass, incomplete patch of CVE-2026-18556
N-able N-central authentication bypass and account takeover. The first fix (CVE-2026-18556) was incomplete. Actively exploited. CISA added it to KEV on 3 August
- CVEConnectWise ScreenConnect auth bypass via an alternate path
ScreenConnect 23.9.7 and earlier skipped authentication on an alternate setup path (CWE-288). Attackers created admin users within hours. CISA KEV. CVSS 10.0. P
- CVEDrupal Simple OAuth/OIDC auth bypass via an alternate path
Drupal Simple OAuth / OIDC 6.0.0 through 6.0.6 allowed authentication to be skipped on an alternate path. Patched in 6.0.7.