Critical N-Able N-Central Vulnerability Allows Hackers to Gain god-mode Access to the RMM Console
ID: 68ed66dd-57d7-51ec-93f6-ba25a9325c52
STIX ID: report--68ed66dd-57d7-51ec-93f6-ba25a9325c52
Feed Name: cybersecurityNews.com
N-able disclosed a critical authentication-bypass vulnerability (CVE-2026-18577) in N-central that enables unauthenticated attackers to achieve full administrative access to managed RMM consoles; the issue affects supported cloud and on‑prem versions, is being actively exploited, and may enable high-impact supply-chain compromises of MSP customers. N-able released a hotfix (2026.3.1.7) and vendors (Huntress) provided IOCs and detection guidance; organizations are urged to apply the hotfix, restrict console exposure, enforce MFA, and review logs and activities for suspicious admin access and remote-control sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
