logo

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

ID: 798e2084-4699-53c4-8778-f87251034fe4

STIX ID: report--798e2084-4699-53c4-8778-f87251034fe4

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

Author: Alexander Culafi

...
...

N-able disclosed active exploitation of a patch-bypass/authentication vulnerability in its N-central RMM product (tracked as CVE-2026-18577, CVSS 8.2) that allowed attackers to obtain administrative access, leverage the "Take Control" feature to pivot into managed environments (including domain controllers), and persist via a Cloudflare tunnel. The vendor released a fix (2026.3.1.7) and urged upgrades; telemetry shows limited confirmed victims but a large potential blast radius for unpatched, self-hosted servers, and Huntress published IOCs and hardening recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.