On 19 August 2026, the Australian Cyber Security Centre (ACSC) issued a bulletin about active exploitation of two authentication bypass vulnerabilities in N-able N-central, a remote monitoring and management (RMM) platform used by IT providers and MSPs around the world, including some in Australia, to manage and monitor their clients' computers, servers and networks from a single console.
This one is worth paying attention to even if you've never heard of N-central. RMM software isn't just another business application, it's the tool many IT providers use to remotely access, patch and control every device they manage. A flaw in that tool doesn't just put one company at risk, it potentially puts every client of every provider using it at risk at once.
What's Actually Happening
Two related vulnerabilities are involved. CVE-2026-18556 was disclosed first, an authentication bypass that let an attacker skip login entirely. N-able shipped a fix, but researchers found the patch didn't fully close the underlying logic flaw, and a second, closely related bypass was assigned CVE-2026-18577. Both have since been confirmed as actively exploited and added to CISA's Known Exploited Vulnerabilities catalogue.
Exploiting these flaws gives an unauthenticated attacker administrative access to the N-central server itself, no valid credentials required. From there, security researchers observed attackers abusing N-central's built-in "Take Control" feature, the same remote-access function IT technicians use for legitimate support, to reach the endpoints that server manages. In at least some cases, attackers then installed Cloudflare Tunnel (a legitimate remote-access tool) on compromised machines to maintain persistent, hard-to-detect access even after the initial hole was noticed.
⚠️ This is what security teams call a "supply chain" style risk: the vulnerability isn't in your business, it's in a tool a third party uses to manage your business. You can do everything right internally and still be exposed if your provider's management platform is compromised.
The Vulnerabilities at a Glance
| CVE | CVSS Score | What It Allows |
|---|---|---|
CVE-2026-18556 | 7.4 (High) | Authentication bypass on the N-central management server |
CVE-2026-18577 | 8.1 (High) | Residual authentication bypass after the original patch, actively exploited in the wild |
N-able has since released Hotfix 2 to address the residual issue, and organisations running N-central, whether an internal IT team or an MSP, should confirm they're patched to the latest version without delay.
Why an RMM Flaw Is Different From a Normal Software Bug
Most vulnerabilities affect one application on one machine. RMM platforms are different by design, they're built to have privileged access across an entire fleet of devices, often for many separate client organisations at once. That's exactly what makes them so useful for legitimate IT management, and exactly why they're such a high-value target for attackers.
This isn't a knock on RMM software generally, tools like N-central, ConnectWise, Datto and others are the backbone of how modern managed IT support actually works, and no reputable provider operates without one. The lesson isn't "RMM is dangerous," it's that the provider's own security discipline around that tool, patching speed, access controls, monitoring for unusual activity, matters just as much as the security work they do on your network directly.
What to Do Right Now
-
1
Ask your IT provider directly If your business is supported by an external IT provider or MSP, ask them plainly: do you use N-able N-central, and if so, have you applied Hotfix 2? A good provider will have an immediate, specific answer.
-
2
If you run N-central in-house, patch now Update to the latest N-central version with Hotfix 2 applied, then review authentication logs for unexpected admin sessions or access from unfamiliar IP addresses.
-
3
Watch for unfamiliar remote-access tools Cloudflare Tunnel and similar tools are legitimate software, which is exactly why attackers use them to blend in. An unexplained new remote-access tool on a business device is worth investigating regardless of why it's there.
-
4
Ask how your provider limits blast radius No RMM platform is ever guaranteed vulnerability-free. What matters is whether your provider segments access, monitors their own management systems, and can tell quickly if something's wrong, not just whether they promise it won't happen.
💡 This is a good moment to ask a broader question: when did your provider last review which third-party tools have privileged access to your systems, and how they'd know if one of those tools was compromised? If you're not confident in the answer, that's worth a conversation.
The Bigger Picture
This is the second major RMM-adjacent, provider-side alert in as many months for Australian businesses, following July's ACSC alert on mass CMS exploitation. The pattern is consistent: attackers are increasingly targeting the infrastructure that manages many businesses at once, because compromising one platform can open the door to dozens of downstream organisations. It's a strong argument for choosing an IT provider that treats its own tooling with the same rigour it applies to yours, and for asking the question rather than assuming the answer.
Reference & Reporting
This article is based on the ACSC's bulletin on active exploitation of N-able N-central: Active exploitation of remote monitoring and management platform within Australia, cyber.gov.au.
If your organisation has been impacted or you suspect a compromise, you can report it and get assistance at cyber.gov.au/report or call the Australian Cyber Security Hotline on 1300 CYBER1 (1300 292 371).
Not sure whether your current IT provider is on top of alerts like this one? BITS can run a free, no-obligation review of your security posture and how your systems are managed. Book a free consultation and we'll tell you exactly where you stand.