T

Threats

ACSC Confirms Active Targeting of N-able N-central Vulnerabilities in Australia

Secure ISS is proactively sharing an update from ASD’s Australian Cyber Security Centre (ACSC) regarding the active exploitation of vulnerabilities affecting N-able N-central. The ACSC has observed targeting of the affected remote monitoring and management platform within Australia. Organisations using N-central, either directly or through a managed service provider, should take action.


Overview

Advisory type: Active Exploitation / Remote Monitoring and Management

Vendor: N-able

Affected product: N-able N-central

Vulnerabilities: CVE-2026-18556 and CVE-2026-18577

Status: Active exploitation, with targeting observed in Australia

N-able N-central is a remote monitoring and management platform used by managed service providers and internal IT teams to administer endpoints and network infrastructure. The identified vulnerabilities can allow authentication to be bypassed, creating a risk of unauthorised access to a high-value administrative control plane.

N-able released patches on 1 August 2026 and subsequently issued Hotfix 2 on 6 August after continued monitoring identified a related attack path. The ACSC has now confirmed that targeting of the vulnerabilities has been observed within Australia.


What Has Been Confirmed

  • The ACSC has observed targeting of the affected N-able N-central vulnerabilities within Australia.

  • CVE-2026-18556 and CVE-2026-18577 are authentication-bypass vulnerabilities affecting current N-central versions, including version 2026.3.

  • N-able released initial patches on 1 August 2026.

  • N-able released Hotfix 2 on 6 August 2026 after identifying a related attack path through continued monitoring.

  • Because N-central can provide extensive administrative access across managed environments, unauthorised access may create risk beyond the management server itself.


Recommended Actions

  • Confirm whether N-central is in use. Check both internally managed systems and services delivered by an external IT or managed service provider.

  • Install the latest vendor-recommended update. Confirm that the applicable patches, including Hotfix 2, have been installed in accordance with N-able’s guidance.

  • Review administrative activity. Examine authentication events, privileged account activity, newly created users, configuration changes and access from unexpected locations.

  • Restrict administrative exposure. Limit access to N-central management interfaces to trusted networks and authorised administrators wherever possible.

  • Validate rather than assume remediation. Installing the update is essential, but it should be accompanied by a review for signs of unauthorised access before remediation.

  • Request assurance from your provider. If N-central is operated by a managed service provider, ask the provider to confirm its use, Hotfix 2 status and whether relevant administrative activity has been investigated.


Reference


Need Help?

If your organisation uses N-able N-central directly or through a managed service provider, Secure ISS can assist with exposure validation, administrative activity review, security monitoring and incident response.

Please contact Secure ISS on 1300 769 460 or email the team for support.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.

Cta Image

Australia is secure when
Australian talent defends it.

Reach out today to discuss how with Lumara, we can work together to protect your business from the always changing Australian threat landscape.