Published on 10 August 2026
Attackers are already inside the networks of German small businesses – not through a fault of the company itself, but through a gap in the remote maintenance software used by their IT service provider. Via the platform N-able N-central, which many IT service providers (so-called MSPs, Managed Service Providers) use to remotely manage their customers' computers, criminals are currently gaining administrative access and installing hidden backdoors directly on the machines of the managed companies. The US cybersecurity agency CISA added the underlying vulnerability CVE-2026-18577 to its catalogue of actively exploited vulnerabilities (KEV, Known Exploited Vulnerabilities) on 3 August 2026. This means: it is not a theoretical risk, but attacks that are happening right now.
N-able N-central is a so-called RMM platform (Remote Monitoring and Management) – software that IT service providers use to centrally handle the maintenance, monitoring and remote control of many customer computers. It is precisely this central role that makes it an attractive target: whoever controls the N-central console potentially controls all connected endpoints.
The new vulnerability CVE-2026-18577 (CVSS score 8.2 out of 10, i.e. "high") is a so-called authentication bypass flaw – a circumvention of the login. It allows a remote attacker to gain administrative access to an N-central server without valid credentials. Particularly galling: the gap arose because an earlier patch for a related vulnerability (CVE-2026-18556) was incomplete. An alternative authentication path remained open – and that is exactly what the attackers are now exploiting.
N-able describes the process clearly in its official statement:
"An attacker had identified a vulnerability on all N-central servers running a version prior to 2026.3.1.7 that allowed them to remotely gain administrative access. After exploitation, the attacker used the Take Control feature and connected to systems within the N-central-managed environment." – N-able
The attack unfolds in several stages. First, the attackers take over the IT service provider's N-central server via the login bypass. From there they abuse the perfectly legitimate "Take Control" function – a remote-control tool that technicians normally use to access customer machines to resolve problems. In the hands of the attackers, this becomes a gateway into every single managed Windows device.
On these endpoints, the attackers then install a particularly persistent backdoor: the ordinarily harmless tool cloudflared.exe (Cloudflare Tunnel). With it they establish an outbound, encrypted tunnel to the internet. The insidious part: such an outbound tunnel requires no open ports in the firewall and even survives reboots, because it is registered as a Windows service (often under the name "Cloudflared"). To disguise it, the attackers often rename the file to innocuous names such as svchost.exe or MicrosoftEdgeUpdate64.exe.
Sophos security researchers describe the approach as follows:
"With the remote-control capability granted by exploiting N-central, the threat actor deployed numerous RMM tools on accessible endpoints … Cloudflare Tunnel was installed on multiple hosts but renamed to disguise it as a harmless file." – Sophos CTU
The crucial problem: even if the N-central server is patched or taken offline, the tunnel on the customers' endpoints remains active. The attackers therefore retain their access even after the actual vulnerability has been closed. Huntress security researchers have already observed how attackers specifically target domain controllers (the central servers for user management), spy on running processes and move laterally through the networks.
"From an MSP's perspective, exploitation of this flaw can grant an attacker full administrative access to an N-central console – the same level of control usually reserved for trusted NOC and technical staff." – Huntress
Affected are all N-central versions up to and including 2026.3.1. It is important for you as a company to understand: you yourself generally do not use N-central directly – but your IT service provider may. And therein lies the danger. This is a classic supply chain attack: it is not your company that is attacked directly, but the service provider that has access to your systems.
The figures illustrate the scale:
Germany's CERT-Bund has now issued an explicit warning as well:
"An attacker can exploit multiple vulnerabilities in N-able N-Central to bypass security measures. Affected are N-able N-Central <2026.3.1.7." – CERT-Bund
First, ask your IT service provider whether they use N-able N-central and which version is installed. The following checks are decisive:
Security updates are already available. N-able reacted quickly and has meanwhile even released a second hotfix. Hosted (cloud) environments are updated automatically by N-able; on-premises customers – i.e. self-operated servers – must patch manually.
The case shows how quickly such attacks develop:
A successful exploitation of this vulnerability generally constitutes a reportable data breach under Art. 33 GDPR. The reason: attackers gain full administrative access to the platform and thereby to the endpoints of the managed companies. This creates a high risk to the confidentiality and integrity of personal data – from employee data through customer data to confidential documents.
Particularly important for the allocation of roles: if an IT service provider (MSP) is compromised, both sides must act. The MSP acts as a processor, while the managed company remains obligated towards the supervisory authority as the controller. The notification to the competent data protection supervisory authority must be made without undue delay, but no later than within 72 hours of becoming aware of the breach. Anyone who misses this deadline risks substantial fines of up to 10 million euros or 2% of annual global turnover.
The risk to small and medium-sized enterprises in Germany must be classified as critical – for several reasons. N-able N-central is widely used among IT service providers. A successful attack on a single MSP can therefore open up the networks of dozens or hundreds of managed customers in one fell swoop. In doing so, the attackers gain not just some access, but highly privileged, administrative access.
Aggravating matters further is that the vulnerability is demonstrably being actively exploited (inclusion in the CISA KEV catalogue) and that the attackers leave persistent backdoors on the endpoints. Therefore: patching the server alone is not enough. Anyone who only updates the N-central server and does not check the endpoints could remain compromised – without noticing. The attackers also specifically target particularly critical systems such as domain controllers and backup servers – precisely the infrastructure that is decisive for a later ransomware extortion or a complete data loss.
This incident vividly demonstrates that your company's security also depends on the security of your service providers. If you work with an IT service provider, you should actively ask now whether N-able N-central is in use, whether it has been updated to version 2026.3.1.10 and – very importantly – whether your endpoints have been examined for the described backdoors.
The good news: a security update is available, and the indicators of compromise are known and verifiable. The bad news: attackers are already active, and a simple update is not enough to eliminate an existing compromise. Act therefore without delay – check your versions, examine your endpoints and document every step so that you can meet your GDPR obligations should the worst come to the worst.