N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able disclosed that attackers used an authentication bypass in N-central to gain remote administrative access, then pivoted through Take Control to reach managed endpoints and install persistent Cloudflare tunnel services. The company has released an emergency fix in build 2026.3.1.7 and urged customers to hunt for compromise indicators, as the initial patch was incomplete. #Ncentral #CVE202618556 #CVE202618577 #TakeControl #Cloudflared

Keypoints

  • Attackers exploited an authentication bypass in N-central to gain admin access.
  • The first patch was incomplete, leading to CVE-2026-18577.
  • Compromised servers were used to reach managed endpoints through Take Control.
  • Attackers installed Cloudflare tunnel services for persistent access.
  • N-able told customers to upgrade to 2026.3.1.7 and hunt for indicators of compromise.

Read More: https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html