Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

High Alert! Aussie cyber agency warns of active exploitation of N-able N-central vulnerability

Hackers are actively targeting Australian organisations using a popular remote monitoring and management platform, ACSC warns.

Thu, 20 Aug 2026
High Alert! Aussie cyber agency warns of active exploitation of N-able N-central vulnerability

The Australian Signals Directorate’s Australian Cyber Security Centre has warned Aussie businesses using N-able’s N-central remote monitoring and management tool that hackers are actively exploiting two flaws in the platform.

“ASD's ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia,” the ACSC said in a High Alert: Act Quickly email circulated late on August 19.

Many managed service providers and enterprise IT departments use the platform to discover, manage, automate, and secure network infrastructure.

 
 

“This alert is relevant to all Australian Managed Service Providers (MSP) and Enterprise IT organisations that utilise the N-able N-central product,” the ACSC said.

“Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product.”

The platform’s developer disclosed both the vulnerability and its exploitation in a 3 August blog post, warning that it impacted all versions of N-central.

The vulnerabilities in question are CVE-2026-18556 and CVE-2026-18577, both of which have a CVSS score of 8.2, making them high-severity bugs. Both are authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel.

The vulnerabilities affect all current versions of N-central, including 2026.3; however, patches are available, with Hotfix 2 released on 6 August 2026.

The platform’s developer, N-able, disclosed both CVE-2026-18577 and its exploitation in an August 3 blog post, warning that it impacted all versions of N-central.

“On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment which led to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server,” N-able said at the time.

According to cyber security firm Rapid7, the vulnerabilities have the potential to be a goldmine for malicious actors.

“Because the platform operates with extensive administrative privileges across customer environments, successful compromise of an N-central server can provide attackers with an efficient path to compromise downstream managed systems,” Rapid7 said in an August 4 blog post.

The ACSC has the following remediation advice for Australian organisations that rely upon N-Central.

  • Review networks and environments for vulnerable versions of N-able N-central.
  • Assess whether the N-central interface needs to remain internet-facing.
  • If N-central is managed by an MSP or IT provider, confirm it has been patched and is being monitored for suspicious activity.
  • Small and medium businesses should check with their MSP or IT provider to determine whether they use N-central.
  • Apply available patches as soon as practicable.
  • Monitor for suspicious activity. N-able has released IoC detection scripts to help identify potential compromise.
  • If suspicious activity is detected, notify the Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC).
Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: