N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
- ID
- 11996
- Status
- summarized
- Published
- 07 Aug 2026, 11:01 PM
- Fetched
- 07 Aug 2026, 11:58 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 4.5
- Created
- 07 Aug 2026, 11:59 PM
- Tags
- Audience
- developersSaaS/startup founders
What happened
N-able confirmed attackers exploited CVE-2026-18577, a critical zero-day in its N-central RMM platform, to gain admin access and then used the platform's Take Control feature to reach downstream customer networks. Attackers registered Cloudflare Tunnel services for persistence after being booted. N-able released Hotfix 2 (version 2026.3.1.10) on August 7, mandatory even for on-premises customers who already applied Hotfix 1 from August 2, though the vendor won't say whether the first fix was bypassed or how many customers were affected.
Why it matters
If you or your MSP runs N-central on-premises, you must install Hotfix 2 immediately even if you already patched — the vendor explicitly says it is not a duplicate. For everyone else, the attack chain (RMM admin access → Take Control feature → Cloudflare Tunnel persistence) is a concrete example of how compromising a management platform becomes a lateral movement route into every downstream system it manages.
Discussion angle
How attack chains through management platforms (RMM, CI/CD, admin consoles) turn a single CVE into a multi-tenant breach — and what that means for founders building tools with privileged downstream access.