(TLP:CLEAR) Vulnerability Notification – N-able N-central Authentication Bypass Actively Exploited
Created: Thursday, August 6, 2026 - 8:18
Categories: Cybersecurity, Security Preparedness
ACTION MAY BE REQUIRED for utilities using N-able N-central remote monitoring and management (RMM), including utilities whose IT or security is managed by a third-party service provider (MSP) that uses N-central. Utilities that outsource technology support may need to consult their MSPs for assistance with remediation actions.
Summary: A critical authentication bypass vulnerability affecting RMM software N-able N-central is being actively exploited in the wild. Tracked as CVE-2026-18556 and CVE-2026-18577 (CVSS 8.2), the vulnerability allows an unauthenticated remote attacker to bypass authentication controls and gain administrative access to affected N-central servers. N-able confirmed active exploitation in an advisory published on August 1, 2026, and released an emergency hotfix yesterday, on August 2.
N-central is an RMM platform primarily used by MSPs and IT teams to centrally monitor, patch, and remotely administer servers and endpoints across many customer environments. This makes the vulnerability especially relevant to the water and wastewater sector: many utilities rely on third-party MSPs for IT and security support, and an MSP’s N-central server sits in a position of privileged, trusted access to every downstream environment it manages. A single compromised N-central server can therefore be used as a force multiplier, pushing scripts, deploying tools, and opening remote-control sessions across all managed endpoints, including domain controllers and other critical systems.
According to N-able, an attacker obtained remote administrative access to affected servers, then abused the built-in Take Control feature to reach systems inside managed environments. On those endpoints, the attacker registered a new service for a Cloudflare tunnel, which preserves the attacker’s access even after the N-central server itself is remediated. Nothing in the reporting indicates Cloudflare itself was compromised; the attacker abused its legitimate tunneling service. Because persistence was established on downstream endpoints, patching N-central alone does not fully remediate an environment that was already compromised.
Remediation Status and Affected Versions
N-able’s initial fix proved incomplete. CVE-2026-18577 covers an authentication bypass that persisted in builds through 2026.3.1. The first unaffected version is 2026.3.1.7, released on August 2, 2026. Both cloud-hosted and on-premises deployments are affected. N-able has indicated that hosted (NCOD) instances will be upgraded automatically on a schedule communicated directly to partners, while self-hosted servers must be upgraded by the customer.
Analyst Note: WaterISAC strongly encourages members and members’ service providers to review N-able’s advisory, determine whether N-central is deployed within or on behalf of their environment, and take the following actions:
- Upgrade N-central to version 2026.3.1.7 or later immediately. Note that upgrading only to 2026.3 is not sufficient.
- If immediate upgrade is not possible, remove internet exposure of the N-central instance or take it offline until the hotfix can be applied.
- Review managed endpoints for unexpected Cloudflare tunnel services (e.g., a service named cloudflared, or svchost.exe running from a user’s Documents folder) that were not intentionally deployed, since patching the server does not remove persistence installed elsewhere.
- Review N-central logs (e.g., ui_access_control.log) for Take Control sessions that cannot be accounted for, and correlate with endpoint Take Control logs under C:\ProgramData\GetSupportService_N-Central\Logs\ (BASupSrvc_*.log.gz). Note that these logs also appear during legitimate use, so presence alone is not proof of compromise.
- Pay particular attention to sessions associated with apparent N-able support identities (for example, ms********@****le.com) that do not correspond to expected support work.
- Audit N-central user accounts for unfamiliar additions or privilege changes, and confirm multi-factor authentication (MFA) is enforced on all accounts.
- Check firewall and endpoint telemetry for traffic to or from the indicators listed below.
Indicators of Compromise (published by N-able)
IP addresses:
- 173.249.252[.]200
- 87.249.138[.]34
- 37.19.210[.]32
- 37.153.90[.]88
- 92.118.112[.]181
- 68.235.46[.]214
Domains:
- mousears.synology[.]me
- wagoosh.direct.quickconnect[.]to
- who-ripped-one.direct.quickconnect[.]to
Note: Security researchers at Huntress determined that the first four IP addresses correspond to Mullvad or NordVPN exit nodes. Blocking these indicators is a temporary, partial control only because attackers can rotate infrastructure, and blocking the initial set should not create a false sense of security. N-able has indicated additional indicators will be shared as they become available.
Additional Reading
