Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
5SEP

N-able hardens N-central as attackers pivot

2 min read
12:09UTC

N-able shipped a second hotfix for N-central on 6 August after watching attacker techniques change. Huntress saw intruders using the console's own remote-control feature to reach the endpoints it manages.

TechnologyAssessed
Key takeaway

N-able's second hotfix lands while attackers use N-central's own remote-control feature to reach managed customer endpoints.

N-able shipped Hotfix 2, build 2026.3.1.10, for N-central on 6 August, adding hardening after watching attacker techniques change 1. N-central is remote monitoring and management software, known in the trade as RMM: the console a managed service provider uses to reach every customer endpoint it looks after. NHS England had alerted UK health organisations on 3 August, citing N-able, that attackers were exploiting CVE-2026-18577 to take over administrative accounts and obtain full administrative access to a server 2.

That flaw is an incomplete fix for CVE-2026-18556, the earlier bug it was issued to close, and both carry a score of 8.2 under version 4 of the Common Vulnerability Scoring System 3. Huntress, a US security firm that watches managed endpoints for its customers, saw attackers use N-central's Take Control feature, the built-in remote-control tool an engineer uses to take over a desktop, to reach the machines the console administers, then run tunnels through Cloudflare's tunnelling service to keep their access 4. Cloudflare's product is being used as designed by people who should not have it, which is a different thing from Cloudflare being breached.

Australia's ACSC, the Australian Signals Directorate's Australian Cyber Security Centre, reported targeting inside Australia on 19 August and said it had no information pointing to any particular sector 5. Two of the three public warnings on this product therefore came from national bodies outside the United States, and both arrived before the vendor's second fix had a fortnight behind it.

Management consoles have been the recurring shape in the federal exploited-vulnerability record all summer, with wide-area network, firewall and management-plane products filling the catalogue in a single ten-day stretch at the end of July . An RMM platform cannot be patched quietly. Taking the console down interrupts monitoring for every customer estate attached to it at once, which is why the date on a second hotfix matters more than the fact of one.

Deep Analysis

In plain English

N-able makes N-central, software that IT companies use to remotely manage their clients' computers. Attackers found a way to abuse a legitimate feature of that software, called Take Control, to jump from one compromised network into others it manages. N-able released a hardening update on 6 August. Australia's cyber agency separately reported attacks using N-central there on 19 August, though it has not said which industry was hit.

Deep Analysis
Root Causes

RMM platforms like N-central exist specifically to give managed service providers privileged remote access into client networks, so any flaw in the platform inherits that same privileged reach for an attacker.

Tunnelling through Cloudflare's infrastructure, rather than a bespoke command server, lets malicious traffic hide inside legitimate CDN traffic that most network monitoring already allows through.

First Reported In

Update #13 · Four privileged platforms under live attack

N-able· 5 Sept 2026
Read original
Causes and effects
This Event
N-able hardens N-central as attackers pivot
An intruder holding a managed service provider's console does not need to move laterally, because the console already reaches everything.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.