CyberzSOC

Publication detail
← Back to advisories & guidance

HIGH ALERT: Active exploitation of remote monitoring and management platform within Australia ↗ source

August 19, 2026 ASD/ACSC Alert

Summary

This alert is relevant to all Australian Managed Service Providers (MSP) and Enterprise IT organisations that utilise the N-able N-central product. Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product. ASD's ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia. N-able N-central is a remote monitoring and management (RMM) platform. MSPs and large enterprise IT departments use it to discover, manage, automate, and secure endpoints and network infrastructure. CVE-2026-18556 and CVE-2026-18577 are authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel.

News Coverage

DateSourceArticle
2026-08-04 The Hacker News CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises CVE-2026-18556
2026-08-03 BleepingComputer N-able warns of N-central auth bypass flaw exploited in attacks CVE-2026-18577
2026-08-03 The Hacker News N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete CVE-2026-18577

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-18556 8.2 High N-able N-central N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
CVE-2026-18577 8.2 High N-able N-central N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-cent…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.