N-able Server Compromise After Incomplete Patch

The recent threat report released by The Hacker News on August 3rd, 2026 highlights a sophisticated attack against the N‑central remote monitoring and management platform used by managed service providers (MSPs) and IT teams. Attackers leveraged an authentication bypass flaw to gain administrative access to N‑central servers and subsequently moved laterally into customer endpoints using the platform’s Take Control feature. The initial patch issued by N‑able did not fully address the vulnerability, resulting in a prolonged window of exposure for all affected deployments.

The attack chain began with exploitation of CVE-2026-18577 (and its predecessor CVE-2026-18556). These vulnerabilities allow an unauthenticated attacker to assume administrative control over N‑central servers that run builds prior to 2026.3.1.7. Once inside the server, attackers used Take Control to remotely access managed endpoints and installed Cloudflare tunneling services on those devices.

The use of Cloudflare tunnels is significant for several reasons:

  • They create outbound connections that bypass typical inbound firewall rules.
  • When installed as Windows services, they survive reboots, providing persistent footholds on compromised endpoints.
  • Because the traffic is routed to Cloudflare’s edge, it is difficult for defenders to block without disrupting legitimate service usage.

After the initial exploitation window closed (as N‑central was patched to 2026.3.1.7), the attackers did not remove the persistence mechanisms they had installed. The tunnels remained active even after the compromised servers were isolated, allowing continuous exfiltration or command and control communication.

N‑able’s response included:

  • Automatic upgrade of hosted N‑central instances to 2026.3.1.7 on a schedule communicated to partners.
  • An advisory for self‑hosted servers to manually apply the patch.
  • A list of six IP addresses associated with the attack traffic: 173.[.]249[.]252[.]200, 87.[.]249[.]138[.]34, 37.[.]19[.]210[.]32, 37.[.]153[.]90[.]88, 92.[.]118[.]112[.]181, and 68.[.]235[.]46[.]214.

Huntress, a rapid response firm, confirmed that one partner account with multiple self‑hosted N‑central instances was compromised. They reported that the attackers accessed nine organizations under that account, touching at least one endpoint per organization. Huntress found no evidence of Cloudflare tunnel installation on those endpoints, suggesting the persistence mechanism varied across incidents.

Indicators of Compromise (IOCs) provided by both N‑able and Huntress include:

  • Unexpected svchost.exe processes located in user Documents folders.
  • A Windows service named Cloudflared.
  • ui_access_control.log and C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz indicating Take Control activity.

Recommendations for security analysts and MSPs:

  • Verify that all N‑central servers are running build 2026.3.1.7 or later. Self‑hosted deployments must apply the patch immediately.
  • Run comprehensive endpoint scans to detect malicious services (e.g., Cloudflared) and orphan processes such as svchost.exe in Documents folders.
  • Correlate logs from N‑central UI, network traffic, and endpoint event logs against the six IP addresses and known attacker domains: mousears.synology[.]me, wagoosh.direct.quickconnect[.]to, and who-ripped-one.direct.quickconnect[.]to.
  • Monitor Take Control sessions for unexpected or unauthorized support identities (e.g., mspsupport@n-able.com).
  • Implement network segmentation to restrict lateral movement from N‑central servers to customer endpoints.

Defenders should also stay alert for future indicators such as the use of VPN exit nodes (Mullvad, NordVPN) as part of attack infrastructure, as identified by Huntress. Continuous monitoring and rapid incident response are essential to mitigate similar authentication bypass attacks in the future.

Leave a Reply

Looking for the Best Cyber Security?

Seamlessly integrate local and cloud resources with our comprehensive cybersecurity services. Protect user traffic at endpoints using advanced security solutions like threat hunting and endpoint protection. Build a scalable network infrastructure with continuous monitoring, incident response, and compliance assessments.

Contact Us

Copyright © 2025 ESSGroup

Discover more from ESSGroup

Subscribe now to keep reading and get access to the full archive.

Continue reading