Full Report
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our
Analysis Summary
# Incident Report: Exploitation of N-central RMM Zero-Day
## Executive Summary
In July 2026, threat actors exploited a zero-day authentication bypass vulnerability in N-able N-central RMM servers to gain administrative access to managed environments. Attackers successfully leveraged built-in remote control features to access downstream client systems, where they established persistent backdoors using Cloudflare Tunnels. N-able has issued multiple urgent hotfixes (ending in .10) to mitigate the flaw and its subsequent bypass.
## Incident Details
- **Discovery Date:** July 31, 2026
- **Incident Date:** Ongoing (first detected late July 2026)
- **Affected Organization:** N-able (and a limited number of downstream customers)
- **Sector:** Managed Service Providers (MSP) / Software
- **Geography:** Global
## Timeline of Events
### Initial Access
- **Date/Time:** July 31, 2026 (Discovery)
- **Vector:** Exploitation of CVE-2026-18577 (Authentication Bypass)
- **Details:** Attackers exploited a flaw in N-central servers that allowed for remote account takeover and administrative access. This vulnerability was an incomplete fix for a previous flaw, CVE-2026-18556.
### Lateral Movement
- **Details:** After compromising the N-central server, attackers used the product's native "Take Control" feature to move from the management server to individual managed endpoints within the customer's environment.
### Data Exfiltration/Impact
- **Details:** The primary impact was the compromise of managed devices. By registering unauthorized services, attackers maintained access to end-user systems even after the initial server-level vulnerability was closed.
### Detection & Response
- **Discovery:** N-able detected unusual activity within a customer environment.
- **Response:** Released Hotfix 1, followed by a more comprehensive Hotfix 2. Published IOCs and a custom service template for endpoint scanning.
## Attack Methodology
- **Initial Access:** Authentication bypass and account takeover (CVE-2026-18577).
- **Persistence:** Registration of a new Windows service for a Cloudflare Tunnel on managed endpoints.
- **Privilege Escalation:** Gaining administrative rights via N-central server exploitation.
- **Defense Evasion:** Use of legitimate RMM features ("Take Control") and "Living off the Land" techniques (Cloudflare Tunnels) to bypass traditional firewall/VPN restrictions.
- **Lateral Movement:** Native RMM remote access tools used to pivot from the management server to client workstations.
- **Impact:** Long-term unauthorized access to downstream managed systems.
## Impact Assessment
- **Financial:** Not disclosed; costs associated with incident response and patching.
- **Data Breach:** Risk of full data access on any managed endpoint compromised via Take Control.
- **Operational:** Disruption for MSPs needing to apply emergency patches and audit all managed endpoints.
- **Reputational:** High; exploitation of a trusted RMM tool used for managing hundreds of client environments.
## Indicators of Compromise
**Network Indicators:**
- 173.249.252[.]176
- 173.249.252[.]200
- 185.156.46[.]150
- 23.234.94[.]43
- 37.153.90[.]88
- 37.19.210[.]32
- 68.235.46[.]214
- 68.235.46[.]235
- 87.249.138[.]34
- 92.118.112[.]181
**Behavioral Indicators:**
- Unexpected registration of Cloudflare Tunnel services on managed endpoints.
- Unauthorized administrative logins to the N-central console.
## Response Actions
- **Containment:** Revocation of compromised N-central server access.
- **Eradication:** Deployment of N-central version 2026.3.1.10 (Hotfix 2).
- **Recovery:** Release of a custom service template to automate the scanning of Windows endpoints for IOCs.
## Lessons Learned
- **Regression and Patch Verification:** The incident highlights the danger of "incomplete fixes" (CVE-2026-18577 failing to fully address CVE-2026-18556).
- **Supply Chain Vulnerability:** RMM tools remain a high-value target because server-level access provides a direct path to hundreds of isolated client networks.
- **Persistence beyond the Server:** Closing a server vulnerability does not automatically remediate downstream persistence (e.g., Cloudflare Tunnels) established during the breach.
## Recommendations
- **Immediate Patching:** All N-central on-premise users must update to version 2026.3.1.10 immediately.
- **Endpoint Auditing:** Use the provided N-able detection template to scan all managed devices for unauthorized services and tunnels.
- **Log Review:** Conduct a thorough audit of N-central logs for "Take Control" sessions initiated from unauthorized administrative accounts.