Following reports of active exploitation across corporate IT environments and managed service providers, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity authentication bypass flaw in N-able N-central servers to its Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026. The action imposes mandatory remediation deadlines for federal civilian agencies and underscores escalating risks surrounding remote monitoring and management (RMM) software.
Escalating Exploitation and Lateral Movement
The vulnerability (tracked as CVE-2026-18577) allows unauthenticated remote attackers to bypass access controls and gain administrative privileges on vulnerable N-central instances. Threat intelligence reports indicate that cybercriminals are actively exploiting the flaw to deploy persistent outbound tunneling tools, such as Cloudflare Tunnels, allowing them to maintain access and pivot directly into connected customer networks.
The KEV catalog addition follows disclosures that initial software patches issued last month were incomplete, allowing threat actors to bypass early fixes. N-able has since released emergency build updates (version 2026.3.1.7 and above) to fully address the underlying flaw.
Key Defense Measures for IT and Security Administrators
In light of active exploitation and government directives, security experts recommend several critical remediation steps:
- Immediate Build Upgrades: Ensure all N-central instances are updated immediately to build
2026.3.1.7or newer to fully mitigate the authentication bypass vector. - Perform Threat Hunting for Tunneling Utilities: Inspect endpoints for unauthorized background services, persistent Cloudflare processes, or unrecognized outbound connections.
- Enforce Zero Trust Endpoint Isolation: Apply strict network segmentation and multi-factor authentication (MFA) across all remote management gateways and administrative portals.
Source: The Hacker News
