ACSC warns of active exploitation targeting N-able N-central in Australia

0

The Australian Cyber Security Centre (ACSC) has issued a high alert warning that it is aware of active exploitation in Australia of vulnerabilities affecting N-able N-central, a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams.

The ACSC said organisations using N-able N-central should assess their exposure and apply vendor mitigations as a priority. The alert lists two vulnerabilities: CVE-2026-18556 and CVE-2026-18577, both rated “HIGH” with a score of 8.2.

According to the ACSC, the vulnerabilities are authentication bypass issues that may allow unauthorised access “through an alternate path or channel”. The agency said the issues affect “all current versions of N-central, including 2026.3”.

The advisory is aimed at “all Australian Managed Service Providers (MSP) and Enterprise IT organisations that utilise the N-able N-central product,” and notes that small to medium businesses should check with their MSP or IT provider to determine whether N-central is in use.

The ACSC said patches were released on 1 August 2026, and that Hotfix 2 was released on 6 August 2026. It advised organisations to upgrade to Hotfix 2 as a priority.

Recommended mitigation steps include reviewing networks for vulnerable versions, reassessing whether the N-central interface needs to be exposed to the internet, applying patches as soon as practicable, and monitoring for suspicious activity. The ACSC also noted that the vendor has released indicator of compromise (IoC) detection scripts intended to help identify compromise.

The agency said it has “no information to indicate that a specific industry or sector is being targeted.”

Organisations that have been impacted, suspect impact, or require assistance can contact the ACSC via 1300 CYBER1 (1300 292 371), according to the alert.

Share.