N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete.
Intelligence analysis by Llama

Attackers took over N-central servers after the initial fix proved incomplete. They exploited an authentication bypass to gain remote access and reach customer systems. N-able has since shipped a new version to fix the issue.
Imagine you have a super powerful tool that lets you control many computers at the same time. But, if someone finds a way to trick the tool into giving them control, they can do bad things to all the computers. That's what happened with N-able's N-central platform. Attackers found a way to trick the tool and took control of many computers.
Analysis
A $60B Vote of Confidence in Remote Monitoring and Management Platforms
N-able's N-central platform is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and IT teams to administer customer endpoints. The platform is designed to provide real-time monitoring, management, and support for customer devices. However, the recent attack on N-central servers highlights the importance of complete and effective patches in preventing security breaches.
Why Cursor?
The attackers exploited an authentication bypass in N-central to gain remote administrative access and reach customer systems managed through those servers. The vulnerability, CVE-2026-18577, affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version. The attackers used Take Control to reach managed endpoints and registered Cloudflare tunnels as services on the devices. The tunnels connect outbound to Cloudflare's edge, so they need no inbound firewall rule or open listening port. Running them as services lets them survive a reboot.
The Road Ahead
N-able has now published six IP addresses seen in the attacks: 173[.]249[.]252[.]200 87[.]249[.]138[.]34 37[.]19[.]210[.]32 37[.]153[.]90[.]88 92[.]118[.]112[.]181 68[.]235[.]46[.]214. Huntress later identified the four addresses from N-able's initial list as Mullvad or NordVPN exit nodes. N-able also told customers to look for svchost.exe in users' Documents folders, a service named Cloudflared, or traffic from the published IP addresses. It advised customers who find any of these indicators to contact support and engage their security teams.
Key points
- Attackers exploited an authentication bypass in N-central to gain remote administrative access and reach customer systems managed through those servers.
- N-able's first fix was incomplete, and the attackers were able to exploit the vulnerability again.
- N-able has since shipped a new version to fix the issue, and customers are advised to upgrade to the latest version.
- The attackers used Take Control to reach managed endpoints and registered Cloudflare tunnels as services on the devices.
- N-able has published six IP addresses seen in the attacks, and Huntress identified the four addresses from N-able's initial list as Mullvad or NordVPN exit nodes.
N-able has since shipped a new version to fix the issue, and customers are advised to upgrade to the latest version. This shows that the company is taking steps to prevent similar attacks in the future.
The attackers were able to exploit the vulnerability and take control of many computers, which could have led to serious consequences. This highlights the importance of complete and effective patches in preventing security breaches.



