N-able is warning customers that attackers are exploiting an authentication bypass vulnerability in its N-central remote monitoring and management (RMM) platform to gain access to customer systems. The issue is tracked as CVE-2026-18577 and affects both hosted and on-premises N-central deployments. Multiple outlets report that the flaw enables unauthorized access to N-central servers, which can then be used to reach endpoints managed through those servers.
According to N-able’s statements cited by reporting outlets, the company detected unusual activity after an increase in licensing-related issues for on-premises N-central customers. N-able says it worked with its security and engineering teams to investigate and respond. The Hacker News reports that N-able’s first remediation did not fully address the problem, and that the initial fix was incomplete.
N-able also identifies affected software versions and remediation timing. One outlet states that CVE-2026-18577 impacts N-central builds prior to 2026.3.1.7. N-able reportedly released version 2026.3.1.7 on August 2 as the first unaffected build.