A critical authentication bypass vulnerability, CVE-2026-18577, in N-able's N-central remote monitoring and management (RMM) software is under active attack. The flaw, which stems from an incomplete patch for a previous vulnerability (CVE-2026-18556), allows unauthenticated remote attackers to gain full administrative access to vulnerable N-central servers. This compromise provides a powerful pivot point, as attackers can then use the RMM's legitimate functions to access and control all downstream customer endpoints managed by the platform. In response to observed exploitation, CISA has added CVE-2026-18577 to its Known Exploited Vulnerabilities (KEV) catalog, and N-able has urged all customers to apply the provided hotfix immediately.
The vulnerability exists because a previous patch for CVE-2026-18556 was insufficient, leaving an alternate path for attackers to bypass authentication mechanisms. A successful exploit grants the attacker the same level of privilege as a system administrator on the N-central server. This is particularly dangerous in an RMM context, as these platforms are designed to have privileged access to thousands of client machines for management purposes.
N-able has confirmed that a "limited" number of its partners have been breached via this vulnerability. Security firms, including Huntress, have also confirmed active exploitation in the wild. The observed attack chain is as follows:
cloudflared.exe) on compromised endpoints. This creates a persistent, outbound-only connection to the Cloudflare network, allowing the attacker to maintain access even if the initial N-central vulnerability is patched.This pattern of exploiting MSP tools represents a significant supply chain risk, as a single compromised RMM server can lead to the breach of hundreds or thousands of downstream organizations.
The impact of this vulnerability is critical for Managed Service Providers (MSPs) and their customers. A compromised N-central server effectively hands the keys to the kingdom to the attacker. They can deploy malware, exfiltrate data, or execute ransomware across the entire fleet of managed devices. The use of Cloudflare Tunnels for persistence complicates remediation, as it provides a stealthy backdoor that may not be detected by traditional firewalls. The financial and reputational damage to an MSP suffering such a breach can be catastrophic, and their clients face severe risks of business disruption and data loss.
The following patterns may help identify vulnerable or compromised systems:
cloudflared.exe*.cfargotunnel.comN-central Audit LogsC:\Program Files (x86)\N-able Technologies\Windows Agent\Detection:
cloudflared.exe or other suspicious processes spawned by the N-able agent. Use D3FEND's Process Analysis capabilities.*.cfargotunnel.com or other known malicious domains. This aligns with D3FEND's Outbound Traffic Filtering.Local Account Monitoring principles can be applied here.Immediate Actions:
cloudflared.exe on managed endpoints.Strategic Hardening:
CISA added both CVE-2026-18577 and CVE-2026-18556 to KEV. New MITRE ATT&CK mappings and refined Cloudflare Tunnel IOCs provided.
Immediately apply the patch from N-able to close the authentication bypass vulnerability.
Mapped D3FEND Techniques:
Restrict network access to the N-central management interface to only trusted IP addresses.
Mapped D3FEND Techniques:
Enforce MFA on all N-central accounts to provide an additional layer of security against account takeover.
Mapped D3FEND Techniques:
Use EDR to detect and block anomalous behavior, such as the N-able agent spawning unauthorized processes like cloudflared.exe.
The primary and most urgent countermeasure against the exploitation of CVE-2026-18577 is to apply the security update provided by N-able. All organizations using N-central must immediately upgrade to version 2026.3.1.7 or a later patched version. Given that this vulnerability is an authentication bypass on an internet-facing management platform, patching is the only way to definitively close the entry vector. Because CISA has added this to the KEV catalog, it confirms active, ongoing attacks. Delaying this patch exposes the entire managed environment to takeover. Patch deployment should be treated as an emergency change, and verification steps must be taken to ensure the update was successfully applied across all N-central instances.
To counter the observed post-exploitation technique, organizations should implement Executable Denylisting (or allowlisting) on managed endpoints. Specifically, create rules to block the execution of cloudflared.exe. Since this tool is used by attackers for persistence, preventing it from running can disrupt their ability to maintain a foothold. This can be achieved through application control solutions like AppLocker or commercial EDR platforms. The rule should be targeted to block the hash of the known malicious binary, or more broadly, block the execution of cloudflared.exe from any directory except for a designated, approved location if it is used for legitimate purposes. This directly counters the attacker's ability to establish a persistent C2 tunnel.
As a critical compensating control, organizations must apply strict Inbound Traffic Filtering to their N-able N-central servers. The management interface should not be exposed to the entire internet. Configure perimeter firewalls to only allow access to the N-central web portal from a limited set of trusted IP addresses, such as the corporate office static IP and the IPs of remote administrators' VPNs. This network-level control acts as a crucial barrier. Even with the CVE-2026-18577 vulnerability present, if an attacker's IP is not on the allowlist, they cannot reach the login page to exploit it. This dramatically reduces the attack surface and mitigates risk while the patch is being deployed or in case future vulnerabilities are discovered.
N-able releases hotfix version 2026.3.1.7 to address CVE-2026-18577.
CISA adds CVE-2026-18577 to its Known Exploited Vulnerabilities (KEV) catalog.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.