On 31 July 2026, N-able noticed an unusual spike in licensing errors from its on-premises N-central customers and started digging. What it found: attackers had been exploiting an authentication-bypass flaw (CVE-2026-18556, CVSS 8.2) to gain unauthenticated administrator access to N-central servers running version 2026.1 or earlier. N-central is remote monitoring and management software — the tool managed service providers use to log into and administer many client networks from one console. N-able shipped a fix in version 2026.2. It didn't work. Attackers found an alternate way through the same flaw that the first patch didn't block, tracked separately as CVE-2026-18577 and affecting every build before 2026.3.1.7, which N-able finally released on 2 August.
The gap between "patched" and "actually fixed" mattered, because once inside a N-central server, attackers didn't stop at the console. They used N-central's own Take Control feature — built for support staff to remotely operate a client's machine — to reach individual managed endpoints, then registered a Cloudflare tunnel as a background service on at least one machine per compromised organisation. That tunnel connects outward to Cloudflare's edge, so it needs no open inbound port and survives a firewall rule change; it also survives the N-central patch, because upgrading the management server does nothing to a backdoor already sitting on an endpoint. Huntress, which first spotted the activity on a customer's self-hosted instance, has confirmed at least nine organisations affected and reported that more than half of reachable N-central servers were still unpatched days after the real fix shipped.
What this means for your business
Most businesses reading this don't run N-central themselves — but a lot of businesses that outsource IT to a managed service provider have no idea what management platform that provider uses. That's the risk worth sitting with here: you can do everything right on your own network and still be exposed because the company you pay to protect it was itself the way in. If your outsourced IT or MSP uses N-able, ask them two direct questions this week — are all your N-central servers on build 2026.3.1.7 or later, and have they specifically checked your endpoints for a Cloudflare tunnel service that shouldn't be there, since patching the server doesn't remove one already planted. More broadly: "we applied the patch" is not the same claim as "the patch actually closed the hole" — this is the second time in a week a vendor's first fix turned out to be incomplete, and it won't be the last. Ask for confirmation, not just a patch note.