CISA has added an actively exploited flaw in N-able N-central to its Known Exploited Vulnerabilities catalog, putting a platform that managed service providers use to administer their customers' networks on the federal must-fix list.
Updated August 4, 2026: N-able's advisory and subsequent analysis have filled in the affected versions, what the attackers did after getting in, and a set of indicators to hunt for. Those details are below.
The agency listed CVE-2026-18577, described in its August 3, 2026 alert as an authentication bypass using an alternate path or channel, on the strength of evidence of active exploitation. That is the bar for entry to the catalog. The flaw lets a remote attacker with no credentials at all skip the login step and take administrative control of a vulnerable N-central server, and it exists because the fix for an earlier bypass, CVE-2026-18556, was incomplete.
Why an RMM flaw is worth moving on
N-central is N-able's remote monitoring and management product. Tools in that category exist to reach into a large number of other people's machines from one console, which is precisely what makes them worth attacking: whoever reaches the console inherits its reach, and for a managed service provider that means client networks as well as its own. That, rather than any published detail about how this specific bug is triggered, is the argument for pulling it out of the routine patch queue.
What's affected
Every version of N-able N-central up to and including 2026.3.1, prior to Hotfix 1, is vulnerable. The fix is N-central 2026.3.1 Hotfix 1, build 2026.3.1.7. Hosted N-central environments are upgraded by the vendor automatically; on-premise deployments have to be patched by hand, and that is where the exposure sits. N-able also advises upgrading N-central agents once the server hotfix is applied.
What the attackers did next
According to N-able, exploitation has been observed in the wild since August 1. After getting in, the intruders used N-central's Take Control function, the built-in feature for remotely operating a managed endpoint, to reach machines behind the console. They then deployed Cloudflare Tunnel (cloudflared), a legitimate tunnelling tool, to establish persistent remote access that does not need an inbound firewall rule. Both steps lean on software an administrator would expect to see, which is what makes them awkward to pick out of logs after the fact. Rapid7's Emergent Threat Response team set out the affected versions and the post-exploitation activity in an August 4 analysis.
What you should do
Apply Hotfix 1 out of cycle rather than at the next scheduled window, then go looking. N-able's guidance is to review systems for indicators of compromise, to contact its support team immediately if evidence of compromise turns up, and to engage incident response if malicious activity is found. Administrators should check for the presence of a Cloudflared service nobody installed, and for a suspicious svchost.exe sitting in a user's Documents folder, which is not where that file belongs. On the log side, review authentication logs, administrative account creation and modification, Take Control session activity, remote management logs and Windows service installation events. The vendor has published a detection template for the flaw.
Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritise rapid remediation of high-risk catalog entries on publicly exposed assets, and also sets expectations for when agencies must check whether attackers compromised a system before the patch was applied. CISA encourages every organisation to adopt the same risk-based approach. The second half of that is the part most often skipped: where exploitation is already happening, patching a management platform without hunting for what came through it beforehand leaves the more expensive problem untouched.
Indicators of compromise
N-able published six IP addresses tied to the activity, defanged here. Review historical network logs for inbound or outbound traffic involving 173[.]249[.]252[.]200, 87[.]249[.]138[.]34, 37[.]19[.]210[.]32, 37[.]153[.]90[.]88, 92[.]118[.]112[.]181 and 68[.]235[.]46[.]214.
IntelFusions tracks additions to the catalog as they land. Recent entries include four SharePoint flaws added during July and exploited Fortinet and Arista bugs. Our earlier look at RMM abuse in incident response data makes the same point from the defensive side.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.