Attackers have actively exploited a high-severity security flaw in N-able's N‑central remote monitoring and management platform, the company disclosed this week. The vulnerability, tracked as CVE-2026-18577, can allow remote administrative takeover of the widely used RMM system without valid credentials. N-able released an emergency hotfix Sunday and is urging all partners and customers to install it immediately, describing the situation as an "active security threat targeting N-central environments."

The authentication bypass flaw carries a severity score of 8.2 out of 10.0 and affects every N-central server version prior to 2026.3.1.7, according to N-able. The vulnerability doesn't require privileges or user interaction, though it's considered to have high attack complexity. Cybersecurity vendor Huntress reported Monday that more than half of reachable N-central cloud servers among its partners and customers hadn't yet received the hotfix. Huntress said it has observed exploitation affecting one customer organization so far, and the company identified a limited number of compromised customers without disclosing specific figures.

After gaining administrative access to vulnerable N-central servers, attackers used the platform's Take Control remote-access feature to connect to managed systems, Huntress reported. They then established Cloudflare tunnels that could maintain access even after removal from the N-central server. Huntress described the resulting access as effectively providing "god-mode" control of the RMM console, enabling attackers to potentially create or modify jobs, execute scripts, change accounts and policies, and launch remote sessions into endpoints managed through the platform. The company noted that threat actors can initiate "remote‑control sessions into servers and workstations, including domain controllers and other critical systems."

N-central is widely used by managed service providers to remotely monitor and manage systems across customer environments, making the vulnerability particularly dangerous for organizations relying on the platform. N-able said it "immediately released an emergency hotfix and directly notified all customers with instructions to upgrade without delay as of today, within 24 hours of discovery of the impact." Because the flaw bypasses normal authentication, Huntress recommended that organizations with N-central servers still broadly reachable from the internet or other untrusted networks should "strongly consider temporarily disabling N-central—up to and including taking the server offline—until N-able's hotfix is available."

For N-able-hosted N-central customers, the company previously applied mitigations to all hosted instances and has begun rolling out the hotfix. On-premises customers must download and install the N-central 2026.3.1.7 update themselves. N-able's investigation is ongoing, and the company is providing customers with updated guidance as new information becomes available. The company said it had identified and directly engaged with compromised customers, though the full scope of affected organizations remains unclear.