CVE-2026-18577: N-able N-central Patch Bypass Puts MSP Networks at Risk
Managed service providers running N-able N-central face renewed exposure after Huntress researchers documented a patch bypass for CVE-2026-18577, a critical authentication flaw in the remote monitoring and management platform. The original fix, released in April 2026, left a logic gap that allows an attacker to invoke privileged API functions using a low-privilege session token.
The bypass explained
N-central's April 2026 patch introduced a server-side authorization check on a set of administrative API endpoints. Huntress found that certain combinations of request parameters caused the check to evaluate incorrectly, returning a successful authorization result for any valid session, including read-only service accounts. An attacker with network access to the N-central console and any legitimate credential can replicate the impact of the original vulnerability despite the patch having been applied.
Versions 23.9 through 24.3 remain affected. N-able released version 24.4 on August 3, 2026 with a corrected authorization check implementation.
Why RMM platforms amplify blast radius
N-central manages endpoints across every downstream client in an MSP's portfolio. A compromised console does not limit an attacker to one organization. The RMM agent installed on managed workstations and servers provides a ready-made remote execution channel into healthcare practices, law firms, and local government offices that may have no direct internet exposure of their own.
Huntress threat intelligence from early 2026 noted that RMM abuse is among the leading initial access vectors for ransomware intrusions targeting mid-market businesses. CVE-2026-18577 is precisely the kind of vulnerability threat actors prioritize: one credential plus one network path translates to hundreds of downstream client targets.
Remediation
Patch to N-central 24.4 immediately. If patching is blocked by a maintenance window, apply the following compensating controls:
- Restrict console access to a dedicated management VLAN or jump host at the network layer, preventing opportunistic access from internet-facing systems.
- Rotate all N-central account credentials, including service accounts with read-only roles.
- Enable multi-factor authentication on every N-central account if not already configured.
- Audit session logs for API calls to administrative endpoints originating from low-privilege accounts.
Huntress has published detection guidance and indicators of compromise through their threat intelligence portal. MSPs should treat this as an emergency patching cycle rather than a standard maintenance window.
Gigia Tsiklauri is a Security Architect and founder of Infosec.ge. Get in touch if you are evaluating RMM platform security or MSP infrastructure risk.