Security researchers and response teams disclosed active exploitation of a critical vulnerability in N-able N-central, a flagship Remote Monitoring and Management (RMM) platform heavily utilized by Managed Service Providers (MSPs) globally. Tracked as CVE-2026-18577 (an incomplete patch for CVE-2026-18556), the flaw enables an unauthenticated remote attacker to execute an authentication bypass and full account takeover on vulnerable N-central instances.

N-able published urgent hotfixes (urging immediate updates to version 2026.3.1.7) after confirming that threat actors were actively taking control of unpatched MSP management servers in the wild.

The Pipeline to Crypto Theft

MSP tooling represents the ultimate "force multiplier" for cybercriminals and drainer groups: