Attackers are taking over the software that manages business PCs — and the first patch didn't hold
Almost every managed business runs some form of remote monitoring and management software — the agent that lets an IT provider patch, monitor and remotely control staff machines. One of the biggest, N-able's N-central, has spent the past fortnight being taken apart. In late July N-able disclosed CVE-2026-18556, an authentication bypass that hands an attacker an administrator account on the N-central server without any credentials at all, and shipped a fix.
The fix didn't hold. Attackers found a second route to the same outcome, forcing a fresh advisory, a second identifier — CVE-2026-18577, also rated 8.2 — and an emergency hotfix in build 2026.3.1.7 on 2 August. In the intrusions N-able investigated, attackers used their new admin access to drive N-central's own Take Control remote-access feature onto managed endpoints, then registered Cloudflare tunnels as services on those machines. Because a tunnel dials out, it needs no inbound firewall rule, and it kept working after the N-central server access was cut off. CISA added the original flaw to its Known Exploited Vulnerabilities catalogue on 5 August. N-able says it has contacted "a limited number of affected customers", and warns that patching the server does not remove tunnels already planted on endpoints.