New! Try the FREE Predictive Security Plugin for WordPress – Scan, Secure & Stay Safe in Seconds!

Current CyberSecurity Advisories

Active exploitation of remote monitoring and management platform within Australia

Release date
19 August 2026
Alert rating
High

Description

Alert on active exploitation in Australia of N-able N-central vulnerabilities CVE-2026-18556 and CVE-2026-18577. Assess exposure and apply mitigations.

Audience

Small & medium businessesOrganisations & Critical InfrastructureGovernment

Current update

This alert is relevant to all Australian Managed Service Providers (MSP) and Enterprise IT organisations that utilise the N-able N-central product. Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product.

This alert is intended for a technical audience.

Background

ASD’s ACSC has observed the targeting of vulnerabilities affecting the N-able N-central product within Australia.

N-able N-central is a remote monitoring and management (RMM) platform. MSPs and large enterprise IT departments use it to discover, manage, automate, and secure endpoints and network infrastructure.

  • CVE-2026-18556 and CVE-2026-18577 are authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel.
  • The vulnerabilities affect all current versions of N-central, including 2026.3.
  • Patches were released on 1 August 2026, with Hotfix 2 released on 6 August 2026. Organisations should upgrade to Hotfix 2 as a priority.

ASD’s ACSC has no information to indicate that a specific industry or sector is being targeted. 

Mitigation advice

ASD’s ACSC advises organisations to ensure the following:

  • Review networks and environments for use of vulnerable versions of the N-able N-central product.
  • Review the need to continue to have the interface exposed to the internet.
  • If your N-able N-central product is managed by a third party, such as a MSP or Enterprise IT provider, you should contact that provider to ensure the products have been patched and are being monitored for suspicious activity.
  • Small to medium business should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product.
  • Apply patches as soon as practicable, if required.
  • Monitor for suspicious activity. Indicator of Compromise (IoC) detection scripts have been released by the vendor, which may assist in detecting compromise. This can be found on the vendor support page.
  • If suspicious activity is detected, notify ASD’s ACSC.

Where to get help

Organisations that have been impacted, suspect impact or require advice and assistance can contact us via 1300 CYBER1 (1300 292 371)

Protect your assets with Predictive

TisaAssist bot
🤖 Hello, how can I assist you today?
I can help you with:
✅ Answer questions related to the website.
✅ Help you understand things you don't know.
❓ What's Tisalabs
💻 What's IoT
🔒 Why sensor data must be protected?