Circuit Wire — a daily news update from the Circuit.
Software firm N-able confirmed this week that attackers exploited an authentication bypass in N-central, its remote monitoring and management platform, to gain administrative control of customer servers. The U.S. Cybersecurity and Infrastructure Security Agency added the flaw, tracked as CVE-2026-18577, to its Known Exploited Vulnerabilities catalog on August 3 and gave federal civilian agencies three days to patch.
N-central is the tool that managed service providers and in-house IT teams use to run fleets of customer endpoints from one console. A break in that console reaches every device beneath it. N-able said it opened an investigation on July 31 after on-premises customers reported an unusual volume of licensing errors, then found that an intruder had gained remote administrative access to servers running build 2026.1 and earlier.
The company's first patch did not hold. It traced the original flaw, CVE-2026-18556, an unauthenticated administrative account takeover, and fixed it in build 2026.2. Attackers then found another route to the same weakness, logged as CVE-2026-18577, which affected builds before 2026.3.1.7. N-able shipped that hotfix on August 2 as the first clean version. Both flaws scored 8.2 on the CVSS scale.
After taking a server, the attackers used N-central's Take Control feature to reach managed endpoints and installed Cloudflare tunnels as services on those machines. The tunnels reach out to Cloudflare's network, so they need no open inbound port, and running them as services keeps them alive through a reboot. N-able said the tunnels preserved access even after the path through the N-central server was cut. Cloudflare itself was not breached.
Security firm Huntress reported the activity at one partner's self-hosted N-central instance, where the attackers reached nine organizations and touched one endpoint in each before disconnecting. N-able has published six attacker IP addresses and told customers to look for a service named Cloudflared or a stray svchost.exe file in user Documents folders. Finland's national cyber security centre warned that every version before the emergency hotfix was exposed. N-able has not said how many customers were hit, how many downstream devices were reached, or who was behind the intrusion.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

