Home / Technology / N-able Flaw: 'God-Mode' Server Access Exposed
N-able Flaw: 'God-Mode' Server Access Exposed
3 Aug
Summary
- Attackers gained administrative control without passwords.
- A second flaw exploited the same weakness missed by initial patch.
- Only the emergency build from August 2nd is now secure.

N-able's N-central remote management software suffered a severe security flaw, granting attackers unauthenticated administrative access. This vulnerability allowed intruders to bypass passwords and gain 'god-mode' control over IT management servers. From these servers, attackers could reach and compromise thousands of client endpoints managed by IT firms.
N-able initially released a patch for CVE-2026-18556, an authentication bypass flaw. However, a subsequent discovery revealed a second exploit path for the same underlying weakness, CVE-2026-18577. This led to an emergency build, version 2026.3.1.7, shipped on August 2nd, being the only version now deemed safe. Earlier builds, including the one advised after the first patch, remained vulnerable.
Attackers leveraged the compromised servers to deploy persistence mechanisms on endpoints, including registering Cloudflare tunnels as Windows services. These tunnels allowed continued access even after the N-central server was patched, highlighting the persistent nature of the threat. N-able advised affected customers to manually hunt down and remove these tunnel services.
The full extent of the compromise remains unclear, as N-able has not disclosed the number of affected customers or downstream devices. However, security firm Huntress noted that a significant portion of N-central servers remained unpatched, posing a widespread risk. The company advised heavily exposed customers to consider taking N-central offline until the fix could be applied.