N-able’s Security Vulnerability Exposes Critical Risks for Legacy Systems N-able, a leading provider of managed service provider (MSP) platforms, disclosed that its N-central software was actively exploited by a critical vulnerability affecting versions prior to 2026.2. The company initially advised customers to upgrade to version 2026.3 as an immediate mitigation step, but further investigation revealed a broader vulnerability surface, prompting a revised disclosure. This incident highlights significant gaps in secure software development lifecycle (SSDLC) practices and underscores the urgent need for robust patch governance and automated security testing in enterprise software ecosystems. The breach, which emerged in late July 2026, initially appeared to be a single-point vulnerability, but mid-investigation, N-able identified an alternative exploit vector. This discovery raised concerns about the adequacy of its initial security response and the broader implications for legacy systems reliant on its platform. N-central is a core component of many MSPs’ infrastructure, managing customer environments and serving as a critical trust anchor. The incomplete characterization of the vulnerability before remediation guidance was issued has amplified downstream risks, as incomplete remediation could leave customer systems exposed to exploitation. The incident coincides with a rapidly evolving Software Lifecycle Engineering (SLE) market, where AI-augmented development practices are becoming standard. According to Futurum Research, 58.6% of SLE decision-makers already mandate automated test coverage thresholds for AI-generated code, reflecting a shift toward proactive security governance.#n_able #n_central #futurum_research #software_lifecycle_engineering #ssdlc
N-able Warns of Authentication Bypass Flaw Exploited in Attacks N-able has issued a warning about a security vulnerability affecting its N-central servers, which allows attackers to bypass authentication mechanisms and gain unauthorized access to systems managed by the platform. The flaw, identified as CVE-2026-18577, was disclosed on August 1st after the vendor detected active exploitation of the vulnerability. The company launched an investigation that uncovered additional security concerns impacting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform. The vulnerability stems from an incomplete patch for CVE-2026-18576, another authentication bypass flaw that affected N-central versions up to 2026.1. Both vulnerabilities could enable threat actors to take over administrative accounts, potentially granting them control over the entire RMM platform. N-able released a hotfix, version 2026.3.1.7, to address the issue, which is required for all N-central instances running versions prior to 2026.3. Hosted deployments have already received the update, while on-premises customers must apply it manually. N-central is an RMM platform used by managed service providers (MSPs) and corporate IT departments to manage large clusters of multi-OS systems and network devices. Compromising these servers could allow attackers to extend their reach beyond N-able’s direct customers, posing a significant risk to the broader ecosystem. The product was previously targeted in zero-day attacks that prompted the Cybersecurity and Infrastructure Security Agency (CISA) to issue an urgent alert. Similar incidents have been reported against other RMM platforms, including Kaseya VSA, ConnectWise ScreenConnect, SimpleHelp, and SolarWinds Orion.#cisa #n_able #n_central #cve_2026_18577 #cve_2026_18576