N-able revealed that hackers used a method of bypassing authentication on their N-central system to gain unauthorized remote control over customer server-managed systems This article explores compromise cloudflare tunneling. . The initial fix was inadequate.
CVE-2026-18577 impacts N-central builds prior to 2026.3.1.7, affecting N-able's customers who have not yet upgraded their systems to version 2026.3.1.7 or later. Following a successful compromise of an N-central server, the attackers employed Take Control to access managed endpoints and register Cloudflare tunnels as services on these devices. These tunnels enable outbound connections to Cloudflare’s edge, eliminating the need for inbound firewall rules or open listening ports. The information provided does not indicate any compromise of Cloudflare's tunneling service; instead, it suggests attackers exploited its tunneling capabilities for nefarious purposes.
The first flaw, CVE-2026-18556, is called "unauthenticated administrative account takeover" in N-able's own CVE record and classified as an authentication bypass through an alternate path or channel. Based on what we know so far, Huntress claims the post-compromise activity was limited to enumerating running processes on endpoints before the attackers disconnected. To detect unauthorized Take Control activity, Huntress suggested examining ui_access_control.log and correlating it with C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz on Windows endpoints.
The company has not disclosed the number or identities of affected customers, how many devices were impacted, when the exploitation began, who is behind it, or if any data was accessed.












