N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

August 3, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Managed Service Providers (MSPs) and IT teams
Incident: Exploitation of an authentication bypass in N-central RMM software to gain unauthorized administrative access.
Impact: Complete administrative takeover of RMM servers and persistent unauthorized access to downstream managed endpoints.
Attacker: Unidentified threat actors
Analysis: Attackers exploited a flaw in N-central to gain administrative control, leveraging the ‘Take Control’ feature to reach downstream endpoints. To maintain persistence, they deployed Cloudflare tunnels on victim devices, effectively bypassing inbound firewall restrictions. The threat was exacerbated by an initial incomplete patch, necessitating a secondary emergency update to fully secure the platform.
Recommendations: Immediately update N-central servers to build 2026.3.1.7 or later.; Audit managed endpoints for unauthorized Cloudflare tunnel services registered as system services.; Review N-central logs for suspicious sessions tied to support identities such as [email protected].
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *