Threat actors are exploiting CVE-2026-18577 (CVSS 8.1) in N-able N-central to deploy RMM tools and establish network tunnels for persistent remote access. The vulnerability affects N-able N-central versions prior to 2026.3. The fixed version is N-able N-central 2026.3.
After compromising systems via CVE-2026-18577, threat actors use the additional RMM tools and network tunnels to establish persistent remote access