Threat Intelligence Brief
Curated summary with source attribution
Source: huntress.com
Threat Risk: High
Victim: Managed Service Providers (MSPs) and their managed customers
Incident: Active exploitation of a critical authentication bypass vulnerability in N-able N-central.
Impact: Full administrative takeover of RMM consoles leading to widespread endpoint compromise and unauthorized remote access.
Attacker: Unidentified threat actors
Analysis: Attackers are leveraging authentication bypasses in N-central to gain full administrative control over RMM servers. Once inside, they abuse built-in remote access features to pivot into managed endpoints and deploy Cloudflare tunnels for persistence. This create a severe supply chain risk where a single compromise impacts numerous downstream organizations.
Recommendations: Immediately update N-central to hotfix version 2026.3.1.7.; Audit N-central UI and remote-access logs for unauthorized administrative activity.; Inspect managed endpoints for unauthorized Cloudflare-based tunnels or dual-use tools.
Source: Huntress
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source