Attackers took over the servers that run thousands of firms’ computers. N-able’s first patch didn’t hold.

A flaw in N-able’s N-central let intruders take administrative control of the remote-management servers that IT firms use to run thousands of client machines, and reach the endpoints behind them. The company patched it, then found the same bug had a second way in. Only the emergency build shipped on 2 August is safe.


Attackers took over the servers that run thousands of firms’ computers. N-able’s first patch didn’t hold.

N-able has told customers that attackers broke into servers running its N-central platform, took administrative control without needing a password, and used that access to reach the customer computers those servers manage. Its first attempt to close the flaw did not fully work. The company shipped a second, emergency fix on 2 August.

N-central is remote monitoring and management software, or RMM. Managed service providers and in-house IT teams use it to patch, monitor, and remotely control thousands of customer machines from one console. That makes an N-central server a rare prize.

Break into one, and you inherit its reach into every endpoint behind it, the same leverage that makes a single master key to a whole cloud database so dangerous.

The security firm Huntress, which published its own analysis, put it bluntly. The flaw hands an attacker unauthenticated “god-mode” access to the console. From there they can push scripts to many or all managed machines, open remote sessions into servers and workstations, including domain controllers, and rewrite the accounts and policies that are meant to keep them out.

A patch that missed

The trouble started as one vulnerability.

N-able’s record calls CVE-2026-18556 an “unauthenticated administrative account takeover,” an authentication bypass that let an attacker reach an admin account without valid credentials. It covered N-central builds up to 2026.1, and the company said it fixed that path in 2026.2. It told customers to upgrade to 2026.3 as an immediate precaution.

Then it kept digging. N-able found a second way to exploit the same underlying weakness that the first patch did not block. N-able’s own record titles the follow-up flaw, CVE-2026-18577, “Incomplete patch leads to administrative account takeover.” It widened the affected range to every build before 2026.3.1.7. Both flaws carry a CVSS 4.0 score of 8.2, and attackers exploited both before the fix landed.

The upshot for customers is stark. Only build 2026.3.1.7, shipped on 2 August, is safe. Upgrading merely to 2026.3, the original advice, is no longer enough. N-able updates hosted instances on a schedule, while customers must patch self-hosted servers themselves.

Finland’s national cyber security centre warned that every version before the emergency hotfix was vulnerable.

How the intruders stayed in

Access was only the start. After taking over a server, the attackers used Take Control, N-central’s built-in remote-access tool, to reach the managed endpoints. On those machines they registered Cloudflare tunnels as Windows services. There is no sign the attackers compromised Cloudflare itself. They simply abused its tunneling service.

The choice was deliberate. A tunnel connects outbound to Cloudflare’s network, so it needs no inbound firewall rule or open port to listen on. Run as a service, it survives a reboot. N-able said the tunnels kept the attackers connected even after it cut the route through the N-central server. Patching the server, in other words, does not evict them.

That is the nasty part of the disclosure. Persistence installed on a downstream endpoint stays there after the upgrade, the way a malicious instruction can survive from one file to the next.

N-able told customers who find evidence of compromise to hunt down and remove the tunnel services themselves. It flagged specific indicators: a file named svchost.exe sitting in a user’s Documents folder, a service called Cloudflared, and traffic to a list of published IP addresses.

How far it spread is still unclear

N-able began investigating on 31 July, after an unusual wave of licensing errors from on-premises customers. It found an attacker had gained administrative access to servers running 2026.1 and earlier. The company said it identified and contacted a limited number of affected customers, but has not given a figure.

Huntress offered the clearest picture so far, and a narrower one. It traced the activity it saw to a single self-hosted N-central instance inside one partner account. From there, the attackers reached nine organisations under that account, touching one endpoint in each. On those machines they only listed running processes before disconnecting.

Huntress also found that four of the addresses on N-able’s initial list were Mullvad or NordVPN exit nodes, not attacker infrastructure.

The bigger worry is how many servers remain open.

At the time of its update, Huntress said more than half of its partners’ and customers’ reachable N-central servers, some 55.6%, were still unpatched. It noted that the appliance runs a custom build of AlmaLinux and rarely has endpoint detection software on it, so intrusions there can go unseen.

The firm advised heavily exposed customers to consider taking N-central offline until they can apply the fix.

Why it matters

The list of unknowns is long. N-able has not said how many customers the attack hit, how many downstream devices it reached, when it began, who is behind it, or whether the intruders took any data. Attackers have hit N-central before, too. US authorities added earlier N-central flaws to their catalogue of actively exploited bugs last year.

It lands in a bruising year for defenders. Researchers have watched AI learn to break in and lock down within days of each other, AI labs have disclosed that their own models breached real companies during tests, and US agencies have warned that intruders are probing critical infrastructure.

What the N-able case shows again is where the leverage sits. The software that manages everyone else’s machines is worth more to an attacker than any single one of those machines.

A bug in it reaches downward by design. A patch that half-closes it is an invitation to try the other half. And persistence planted on the endpoints outlives the fix on the server.

For the IT providers that run N-central, the job does not end at clicking upgrade.

Get the TNW newsletter

Get the most important tech news in your inbox each week.