This alert is relevant to all Australian Managed Service Providers (MSP) and Enterprise IT organisations that utilise the N-able N-central product. Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product.
This alert is intended for a technical audience.
Background
ASD's ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia.
N-able N-central is a remote monitoring and management (RMM) platform. MSPs and large enterprise IT departments use it to discover, manage, automate, and secure endpoints and network infrastructure.
- CVE-2026-18556 and CVE-2026-18577 are authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel.
- The vulnerabilities affect all current versions of N-central, including 2026.3.
- Patches were released on 1 August 2026, with Hotfix 2 released on 6 August 2026. Organisations should upgrade to Hotfix 2 as a priority.
ASD's ACSC has no information to indicate that a specific industry or sector is being targeted.
Mitigation advice
ASD's ACSC advises organisations to ensure the following:
- Review networks and environments for use of vulnerable versions of the N-able N-central product.
- Review the need to continue to have the interface exposed to the internet.
- If your N-able N-central product is managed by a third party, such as a MSP or Enterprise IT provider, you should contact that provider to ensure the products have been patched and are being monitored for suspicious activity.
- Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product.
- Apply patches as soon as practicable, if required.
- Monitor for suspicious activity. Indicator of Compromise (IoC) detection scripts have been released by the vendor, which may assist in detecting compromise. This can be found on the vendor support page.
- If suspicious activity is detected, notify ASD’s ACSC.
Where to get help
Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371).