Australian businesses and IT providers using N-able N-central need to take immediate notice of a new cybersecurity warning.

The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) has issued a High-rated cybersecurity alert after observing active targeting of vulnerabilities affecting the N-able N-central remote monitoring and management platform within Australia.

The vulnerabilities, identified as CVE-2026-18556 and CVE-2026-18577, can potentially allow attackers to bypass authentication and gain unauthorised access to vulnerable N-central systems.

For Australian businesses, particularly organisations relying on a Managed Service Provider (MSP) for IT management, this is an important reminder that the security of remote management platforms can directly affect the security of every device they manage.

What Is N-able N-central?

N-able N-central is a Remote Monitoring and Management (RMM) platform commonly used by Managed Service Providers and enterprise IT departments.

Platforms such as N-central allow IT providers to remotely monitor, manage, patch and support computers, servers and network infrastructure.

This level of access makes RMM platforms extremely useful for legitimate IT management — but it also means they can become attractive targets for cybercriminals.

If an attacker gains administrative access to an RMM platform, they may potentially gain a pathway into multiple managed systems.

This is one reason businesses should ensure their IT environment is supported by a provider that takes cybersecurity and proactive IT protection seriously.

What Has Happened?

On 19 August 2026, the ASD’s Australian Cyber Security Centre issued an alert confirming that vulnerabilities affecting N-able N-central were being targeted within Australia.

The two vulnerabilities are:

  • CVE-2026-18556
  • CVE-2026-18577

According to the ACSC, these authentication bypass vulnerabilities may allow unauthorised access through an alternate path or channel.

N-able has also confirmed that on 31 July 2026, its security monitoring detected unusual activity inside a customer environment and identified a threat actor actively exploiting a previously unknown vulnerability in N-central.

The incident was therefore not simply theoretical. Exploitation had already occurred.

How Were Attackers Using the Vulnerability?

N-able’s investigation found that an attacker was able to obtain remote administrative access without authentication.

Once inside an affected N-central environment, the attacker was observed using N-central’s legitimate Take Control remote-access functionality to connect to managed endpoints.

The attacker was also observed registering Cloudflare tunnel services on managed devices.

This is particularly important because it could provide an attacker with a persistence mechanism that remains available even after their original access to the N-central server has been removed.

This type of activity highlights why cybersecurity cannot rely on a single layer of protection. Businesses need a combination of patch management, endpoint protection, monitoring, secure authentication and reliable backup and data protection.

Hotfix 1 Is Not Enough

N-able initially released Hotfix 1, build 2026.3.1.7, to address the first identified attack path.

However, continued investigation identified an additional related attack path.

N-able subsequently released:

N-central 2026.3 Hotfix 2
Build: 2026.3.1.10

Hotfix 2 supersedes Hotfix 1.

Organisations running self-hosted N-central should therefore not assume they are fully protected simply because Hotfix 1 was previously installed.

N-able states that organisations using self-hosted N-central should upgrade to 2026.3.1.10 as soon as possible.

For N-able-hosted N-central environments, N-able advises that the necessary mitigations have already been applied.

Installing the Patch Is Only the First Step

One of the most important points from N-able’s security update is that applying Hotfix 2 closes the vulnerability, but it does not automatically remove an attacker who may already have gained access.

N-able has reported that attackers were observed creating new accounts and resetting existing accounts in an attempt to maintain access.

Therefore, organisations that operated vulnerable N-central systems — particularly where patching was delayed — should not consider the installation of Hotfix 2 to be the end of the incident response process.

Indicators That Should Be Investigated

N-able has published several Indicators of Compromise (IoCs) and suspicious behaviours associated with the incident.

These include:

  • Unexpected or suspicious N-central administrator logins
  • Unexpected creation of new user accounts
  • Unexplained password resets
  • Unusual Take Control activity
  • Unauthorised activity on managed endpoints
  • A service registered as Cloudflared
  • A suspicious file named svchost.exe located within a user’s Documents directory

A clean Indicator of Compromise scan should also not automatically be treated as proof that an environment was never accessed. Logs, accounts, administrative activity and endpoints should still be reviewed as part of a broader investigation.

Seven Actions Australian Businesses Should Take

1. Ask Your IT Provider Whether They Use N-central

If your organisation outsources its IT support, ask your Managed Service Provider whether N-able N-central is used to manage your systems.

The ACSC specifically recommends that small and medium businesses engage with their MSP or enterprise IT provider to determine whether the product is in use.

2. Confirm Hotfix 2 Has Been Applied

If a self-hosted N-central environment is being used, confirm that it has been upgraded to:

2026.3.1.10 — N-central 2026.3 Hotfix 2

Do not rely solely on confirmation that an earlier hotfix was installed.

3. Review Internet Exposure

The ACSC recommends reviewing whether the N-central management interface needs to remain directly exposed to the internet.

Reducing unnecessary external exposure is an important principle of good network security.

SwiftTech can assist businesses with secure network infrastructure, segmentation and monitoring to reduce unnecessary attack surfaces.

4. Audit Accounts and Administrative Access

Review all N-central accounts and administrative privileges.

Look for:

  • Unknown users
  • Unexpected administrator accounts
  • Recently created accounts
  • Password resets that cannot be explained
  • Unusual login times or locations

Multi-factor authentication should also be enforced wherever supported.

Australian businesses can further strengthen their security posture by adopting controls from the ACSC Essential Eight cybersecurity framework.

5. Check Managed Endpoints for Persistence

Because attackers were observed using Take Control and Cloudflare tunnelling, organisations should also investigate the computers and servers managed through affected N-central environments.

Simply securing the N-central server itself may not remove persistence mechanisms that have already been installed elsewhere.

6. Strengthen Monitoring, Endpoint Security and Backups

This incident demonstrates the importance of layered security.

Businesses should have appropriate:

  • Endpoint monitoring
  • Security patch management
  • Endpoint Detection and Response (EDR)
  • Multi-factor authentication
  • Security logging
  • Account monitoring
  • Encrypted offsite backups
  • Tested disaster recovery procedures

SwiftTech provides business IT support and managed IT services designed to proactively monitor, maintain and protect business technology environments.

Businesses should also maintain independent and recoverable copies of critical information through a properly designed backup and disaster recovery strategy.

7. Treat Suspicious Activity as a Potential Security Incident

If evidence of compromise is discovered, preserve relevant logs and evidence and begin an incident-response process.

Affected Australian organisations can also report cybersecurity incidents to the ASD’s Australian Cyber Security Centre.

Why This Matters to Business Owners

You do not need to personally operate an N-central server for this issue to be relevant to your business.

Your IT provider may use an RMM platform behind the scenes to support your computers, servers and network.

These tools often have extensive administrative capabilities because they are designed to:

  • Install software
  • Deploy security updates
  • Monitor systems
  • Run administrative commands
  • Access computers remotely
  • Manage large numbers of endpoints

That makes the security of the management platform itself critical.

Cybersecurity should therefore be viewed as more than simply installing antivirus software. Businesses need to consider how their devices, networks, cloud services, administrative accounts, backups and remote-management systems work together.

A Broader Cybersecurity Lesson

No software platform can be guaranteed to remain vulnerability-free forever.

What matters is how quickly vulnerabilities are identified, patches are applied, suspicious activity is detected and affected environments are investigated.

This is why proactive management is significantly different from simply waiting until something breaks.

A properly managed environment combines regular patching, monitoring, access control, endpoint security, backups and incident response.

Microsoft 365 environments should receive the same attention. As discussed in our recent article, modern phishing attacks can sometimes bypass traditional MFA techniques. You can read more in Microsoft 365 Phishing Can Bypass MFA — Is Your Business Properly Protected?

How SwiftTech Can Help

If you are unsure whether your business has been exposed, SwiftTech can help review your current IT and cybersecurity environment.

Our services include:

  • Cybersecurity assessments
  • Managed IT services
  • Endpoint monitoring and protection
  • Security patch management
  • Microsoft 365 security
  • Network security
  • Essential Eight implementation
  • Encrypted backup and disaster recovery
  • Security monitoring and incident investigation

Learn more about SwiftTech cybersecurity solutions or explore our complete range of IT services.

Concerned about the security of your business?

Contact SwiftTech to arrange a cybersecurity and IT security review.

Call 1800-0-SWIFT (1800 079 438)
www.swifttech.com.au

Stay protected. Stay productive. Partner with SwiftTech.


Frequently Asked Questions

What N-able N-central vulnerabilities are being actively exploited?

The Australian Cyber Security Centre has identified targeting involving CVE-2026-18556 and CVE-2026-18577. These vulnerabilities can potentially allow authentication bypass and unauthorised access to vulnerable N-central systems.

What version of N-central should organisations install?

Self-hosted N-central environments should be upgraded to N-central 2026.3 Hotfix 2, build 2026.3.1.10. Hotfix 2 supersedes the earlier Hotfix 1 release.

How did attackers use compromised N-central systems?

N-able reported that an attacker obtained remote administrative access and used N-central’s Take Control functionality to access managed endpoints. Cloudflare tunnel services were also observed being registered on endpoints to provide persistence.

How can I tell whether my business was affected?

Businesses should first determine whether their IT provider uses N-able N-central. Where exposure is possible, administrators should review N-central versions, user accounts, login activity, Take Control activity, endpoint changes and the Indicators of Compromise published by N-able.

What should businesses that do not use N-central do?

The incident is still an important reminder to keep software patched, enforce multi-factor authentication, limit unnecessary internet exposure, monitor privileged accounts and maintain secure, tested backups. The ACSC’s Essential Eight framework provides a useful baseline for improving cybersecurity resilience.


References

This article is provided for general cybersecurity awareness and informational purposes. Cybersecurity incidents should be assessed according to the circumstances of the affected environment.