Attackers breach N-able N-central RMM servers
N-able has released four hotfixes since attackers first bypassed N-central logins and reached managed customer computers. Huntress found a server with Hotfix 2 compromised on September 4. The newest flaw, a maximum-severity hole that lets an attacker run code on the server without logging in at all, is now on the US government's list of bugs known to be under attack, with a September 11 deadline for federal agencies to patch. On September 10, Rapid7 opened a draft Metasploit module for the newest flaw.
- Started
- Aug 1, 2026
- Latest activity
- Sep 10, 2026
- Attributed to
- Not confirmedNo credible attribution yet
- Where
- United States
- Sectors
- Technology, Multiple sectors
- Scale
- N-central is used by managed service providers to run thousands of client organizations' computers
Current status
No credible update dated after September 10, 2026 was found.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Impact
Attackers used the August login bypass to gain administrative control, reach managed customer computers, and create ways to keep access. Huntress says it saw exploitation attempts tied to all three waves of flaws, including scans of a specific N-central web address and new admin accounts created with a telltale invalid email address. Huntress worked with N-able and Cloudflare to shut down the tunnels attackers were using to stay inside compromised systems. Rapid7's draft exploit module was tested against unpatched N-central versions and the vendor's Hotfix 4 was verified to block it.
What to do
Install N-central 2026.3.1.14 (Hotfix 4) immediately; this is now a federally mandated deadline of September 11 for US government users. Check logs for scans of the remoteControlAction.do getPierDetails address and for any new admin accounts with an email ending in .invalid. Audit all users and permission changes, and allow access to the N-central login page only from approved internet addresses or through a VPN.
Timeline
-
Sep 10, 2026
Rapid7 opened a draft Metasploit pull request for CVE-2026-86218. The module was tested against unpatched N-central versions, while N-central 2026.3.1.14 was verified to block the exploit.
Activegithub.com -
Sep 8, 2026
CISA added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog and ordered US federal agencies to patch by September 11.
Activecisa.gov -
Sep 7, 2026
Security researchers confirmed CVE-2026-86218 as a maximum-severity, CVSS 10.0 pre-auth remote code execution flaw. Huntress said it saw exploitation attempts across all three vulnerability waves, spotting attackers probing a specific N-central web address and creating admin accounts with email addresses ending in .invalid. Huntress worked with N-able and Cloudflare to disrupt the tunnels attackers used to keep access.
Activeforkast.news -
Sep 6, 2026
N-able released Hotfix 4 for CVE-2026-86218 and said the flaw had been exploited. It also reported scans attempting to exploit it.
Activen-able.com -
Sep 5, 2026
N-able released Hotfix 3 for CVE-2026-86206 and CVE-2026-86207, which could bypass login controls and give an attacker full access to N-central.
Activestatus.n-able.com -
Sep 4, 2026
Huntress began investigating after a customer server running Hotfix 2 was compromised. Limited logs prevented it from confirming which flaw the attacker used.
Activehuntress.com -
Aug 10, 2026
N-able said attackers had reached managed computers and set up Cloudflare tunnels to keep access after they were removed from N-central.
Activen-able.com -
Aug 7, 2026
Microsoft said Storm-1175 began deploying StormEncryptor ransomware on August 2 and likely exploited CVE-2026-18577, but it hadn't confirmed the link.
Activebsky.app -
Aug 6, 2026
N-able found another attack path and released Hotfix 2. It said the investigation remained active and a limited number of customers had been affected.
Activen-able.com -
Aug 5, 2026
CISA ordered US federal agencies to patch the N-central flaws, along with separate bugs in Langflow and Apache Tomcat, within three days.
Activebleepingcomputer.com -
Aug 3, 2026
Security outlets reported N-able confirmed attackers had broken into N-central servers and reached the customer computers those servers manage.
Activethenextweb.com -
Aug 2, 2026
N-able disclosed that its first patch was incomplete and a second flaw, CVE-2026-18577, let attackers bypass login again and take over accounts.
Activenvd.nist.gov -
Aug 1, 2026
CISA added an N-able N-central authentication bypass flaw, CVE-2026-18556, to its Known Exploited Vulnerabilities catalog.
Emergingnvd.nist.gov
Sources
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws BleepingComputer Aug 5, 2026
- Attackers took over the servers that run thousands of firms' computers. N-able's first patch didn't hold. The Next Web Aug 3, 2026
- Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Dark Reading Aug 3, 2026
- N-able N-central Flaw Sees Exploitation: 5 Things To Know CRN Aug 3, 2026
- N-able N-central authentication bypass CISA KEV Aug 1, 2026
- N-able N-central login bypass under active attack CISA KEV Aug 2, 2026
- N-central Security Update - August 10, 2026 N-able Aug 10, 2026
- Storm-1175 begins deploying StormEncryptor Microsoft Threat Intelligence Aug 7, 2026
- N-able N-central Vulnerability Exploitation Huntress Sep 6, 2026
- N-central Security Update - Take Action to Apply 2026.3 HF4 N-able Sep 6, 2026
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw The Hacker News Sep 7, 2026
- N-able patches critical N-central zero-day exploited in the wild Help Net Security Sep 7, 2026
- CVE-2026-86218 added to Known Exploited Vulnerabilities Catalog CISA Sep 8, 2026
- N-central 2026.3 Hotfix 4 - CVE-2026-86218 N-able Status Sep 6, 2026
- N-able N-central CVSS 10.0 Pre-Auth RCE Marks Third Attack Wave in Six Weeks Forkast Sep 7, 2026
- Patch now! Hackers are targeting yet another N-able N-central vulnerability Cyber Daily Sep 9, 2026
- N-able issues patch for zero-day flaw Yahoo Tech Sep 8, 2026
- CVE-2026-86218 Detail NVD Sep 6, 2026
- Add exploit module for N-able N-central unauthenticated RCE (CVE-2026-86218) GitHub Sep 10, 2026
Related reports
- N-able N-central Authentication Bypass by Primary Weakness Sep 9, 2026
- N-central flaw allows code execution without login Sep 7, 2026
- N-central flaw lets attackers run code with no login Sep 6, 2026
- CISA warns of active attacks on Langflow, N-central, Tomcat Aug 5, 2026
- N-able N-central login bypass under active attack Aug 2, 2026
- N-able N-central bug can let attackers skip login Aug 1, 2026