Skip to main content

N-able N-central Authentication Bypass Exploited to Compromise Managed Endpoints via Cloudflare Tunnels (CVE-2026-18577)

Scope: N-able N-central All Versions Prior to 2026.3.1.7 (Hosted and On-Premises)

Severity: Red

Attackers exploited an incomplete fix for an earlier N-central authentication bypass (CVE-2026-18556) to discover a second bypass path (CVE-2026-18577) affecting all N-central versions prior to 2026.3.1.7, taking over N-central server instances, pivoting to all managed customer endpoints via the built-in Take Control feature, and establishing persistent Cloudflare tunnels registered as Windows services on compromised endpoints that survive reboots and require no inbound firewall rules, making them extremely difficult to detect and remove through standard network monitoring. N-central is a remote monitoring and management platform used by managed service providers and enterprise IT teams to centrally administer large fleets of endpoints, meaning a single compromised N-central instance provides silent administrative access to every device under its management. Organizations must upgrade to N-central version 2026.3.1.7 immediately, audit all managed endpoints for svchost.exe in user Documents folders and a service named Cloudflared as indicators of post-exploitation persistence, and block the attacker IP addresses published in N-able's security bulletin.

The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.