The vendor confirmed that intruders rode an authentication bypass in N-central, its remote monitoring and management platform, to take over servers with administrative rights and move into customer environments managed through them. A first round of remediation turned out not to close the door.
The original flaw, tracked as CVE-2026-18556, is an unauthenticated administrative account takeover scored 8.2 on the CVSS 4.0 scale. N-able believed it fixed the path in release 2026.2, but attackers found an alternative route, now tracked as CVE-2026-18577, affecting builds before 2026.3.1.7. The vendor shipped that hotfix on August 2 after spotting an unusual volume of licensing errors on July 31.
Using the Take Control feature, the intruders moved from the hijacked N-central server to managed endpoints and left Cloudflare tunnels running as services on them. Because tunnel traffic flows outbound to Cloudflare’s edge, no inbound firewall rule or open port is required, and the services ride out reboots, so access survived even after the route through N-central was cut. N-able stresses that Cloudflare was not breached; its tunneling service was simply abused.
Security firm Huntress identified four of the attacker IPs as Mullvad and NordVPN exit nodes and published three domains tied to the activity. N-able has shared indicators of compromise, including a service named Cloudflared and svchost.exe running from Documents folders.
Every N-central customer should move to 2026.3.1.7; upgrading to 2026.3 is no longer enough, and hosted instances will be patched on a communicated schedule. Anyone who spots signs of intrusion must also sweep managed endpoints for rogue tunnel services, since patching N-central does not erase persistence already planted on other machines.
