Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

N-able has disclosed a critical security vulnerability in its N-central remote monitoring and management (RMM) platform, which could allow unauthenticated attackers to gain full administrative, or “god-mode,” access to the RMM console.

This issue affects all currently supported N-central versions, including both cloud-hosted and on-premises deployments, and it is being actively exploited in the wild.

The vulnerability is tracked as CVE-2026-18577 and follows an earlier advisory for CVE-2026-18556 according to the CVE description cited by Huntress, an incomplete fix for the earlier issue enabled authentication bypass and account takeover in N-central versions up to 2026.3.1.

This means that a remote attacker could potentially access the management platform without valid credentials and assume the privileges typically reserved for managed service provider (MSP) administrators and engineering teams.

Managed service providers widely use n-central to monitor, patch, automate, and remotely control customer endpoints. As a result, compromising a single N-central server can lead to a high-impact supply-chain incident affecting many downstream organizations.

An attacker with console-level access could push scripts, deploy tools, create jobs, change roles and policies, or launch remote-control sessions against servers and workstations managed through the platform.

N-ABLE N-CENTRAL Vulnerability

In response to this vulnerability, N-able released hotfix version 2026.3.1.7 on August 2 and urged customers to upgrade immediately. The vendor’s status page indicates that this update addresses CVE-2026-18577 and supports upgrades from versions 2025.4, 2026.1, 2026.2, and 2026.3.

Customers using older versions should first transition to a supported upgrade path before applying the hotfix. Huntress has reported observing exploitation affecting at least one organization within its customer base.

N-able’s security advisory (source :huntress )

Their investigation suggests that attackers may misuse N-central’s Take Control function to pivot into managed systems and deploy Cloudflare-based tunnels for persistent access. Full root cause details have not yet been published, so security teams should consider the available detection guidance to be evolving.

Administrators are advised to prioritize patching and minimize exposure during the upgrade process. N-central consoles should not be broadly accessible from the public internet. Organizations should limit access through firewall rules, known IP ranges, VPN connections, and single sign-on where available.

Furthermore, multi-factor authentication (MFA) should be enforced for every N-central account. However, it is important to note that MFA alone does not mitigate the risks associated with an authentication-bypass vulnerability.

Security teams should review N-central login, account, job, and remote-control activities for anomalies. High-priority events to monitor include unfamiliar administrator accounts, unexpected privilege changes, large automation jobs, unusual access times, and remote sessions targeting critical infrastructure such as domain controllers and file servers.

Endpoint investigators can examine Take Control-related logs in the directory C:ProgramDataGetSupportService_N-CentralLogs, while being mindful that these logs may also be generated by legitimate support activity.

N-able and Huntress have identified several suspicious IP addresses and domains for investigation. However, defenders should not rely solely on blocking these indicators, as attackers can rapidly change their infrastructure.

Any suspicious connection to an N-central console should trigger an incident response review that includes an assessment of affected endpoints, accounts, scripts, and remote sessions following the suspected intrusion.

Type IOC
IP address 173.249.252[.]200
IP address 87.249.138[.]34
IP address 37.19.210[.]32
IP address 68.235.46[.]214
IP address 37.153.90[.]88
IP address 92.118.112[.]181
Domain mousears.synology[.]me
Domain wagoosh.direct.quickconnect[.]to
Domain who-ripped-one.direct.quickconnect[.]to

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.