N-central Patch Miss Left Managed Endpoints Exposed

Fixing the N-central server is not enough if the attacker has already turned it into a bridge into customer endpoints. In this case, the first patch for the authentication bypass was incomplete, and attackers used the gap to reach managed systems and plant Cloudflare tunnel services that kept access alive even after the server-side route was cut off. N-able says CVE-2026-18556 and CVE-2026-18577 affect builds through 2026.3.1, with 2026.3.1.7 as the first fixed version. The abused tunnels run as services on the endpoints, call out to Cloudflare over outbound connections, and survive reboot, so patching the RMM server alone does not remove the foothold already placed on the fleet. For MSPs and IT teams, the management plane is now part of the endpoint persistence problem. If N-central was compromised, the trusted remote-control path may already have been converted into long-lived access on customer machines.

Part of the PlainSec briefing for 2026-08-03

Every edition of this story: N-central Patch Miss Left Managed Endpoints Exposed

Sources