T
Threats
ACSC Confirms Active Targeting of N-able N-central Vulnerabilities in Australia
Secure ISS is proactively sharing an update from ASD’s Australian Cyber Security Centre (ACSC) regarding the active exploitation of vulnerabilities affecting N-able N-central. The ACSC has observed targeting of the affected remote monitoring and management platform within Australia. Organisations using N-central, either directly or through a managed service provider, should take action.
Overview
Advisory type: Active Exploitation / Remote Monitoring and Management
Vendor: N-able
Affected product: N-able N-central
Vulnerabilities: CVE-2026-18556 and CVE-2026-18577
Status: Active exploitation, with targeting observed in Australia
N-able N-central is a remote monitoring and management platform used by managed service providers and internal IT teams to administer endpoints and network infrastructure. The identified vulnerabilities can allow authentication to be bypassed, creating a risk of unauthorised access to a high-value administrative control plane.
N-able released patches on 1 August 2026 and subsequently issued Hotfix 2 on 6 August after continued monitoring identified a related attack path. The ACSC has now confirmed that targeting of the vulnerabilities has been observed within Australia.
What Has Been Confirmed
The ACSC has observed targeting of the affected N-able N-central vulnerabilities within Australia.
CVE-2026-18556 and CVE-2026-18577 are authentication-bypass vulnerabilities affecting current N-central versions, including version 2026.3.
N-able released initial patches on 1 August 2026.
N-able released Hotfix 2 on 6 August 2026 after identifying a related attack path through continued monitoring.
Because N-central can provide extensive administrative access across managed environments, unauthorised access may create risk beyond the management server itself.
Recommended Actions
Confirm whether N-central is in use. Check both internally managed systems and services delivered by an external IT or managed service provider.
Install the latest vendor-recommended update. Confirm that the applicable patches, including Hotfix 2, have been installed in accordance with N-able’s guidance.
Review administrative activity. Examine authentication events, privileged account activity, newly created users, configuration changes and access from unexpected locations.
Restrict administrative exposure. Limit access to N-central management interfaces to trusted networks and authorised administrators wherever possible.
Validate rather than assume remediation. Installing the update is essential, but it should be accompanied by a review for signs of unauthorised access before remediation.
Request assurance from your provider. If N-central is operated by a managed service provider, ask the provider to confirm its use, Hotfix 2 status and whether relevant administrative activity has been investigated.
Reference
ASD’s ACSC — Active exploitation of remote monitoring and management platform within Australia
iTnews — ASD warns of Australian attacks on N-able N-central RMM
Need Help?
If your organisation uses N-able N-central directly or through a managed service provider, Secure ISS can assist with exposure validation, administrative activity review, security monitoring and incident response.
Please contact Secure ISS on 1300 769 460 or email the team for support.

