ACSC warns of active exploitation targeting N-able N-central in Australia

The Australian Cyber Security Centre (ACSC) has issued a high alert warning that it is aware of active exploitation in Australia of vulnerabilities affecting N-able N-central, a remote monitoring and management (RMM) platf

ACSC warns of active exploitation targeting N-able N-central in Australia

ACSC warns of active exploitation targeting N-able N-central in Australia


The Australian Cyber Security Centre (ACSC) has issued a high alert warning that it is aware of active exploitation in Australia of vulnerabilities affecting N-able N-central, a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams.

The ACSC said organisations using N-able N-central should assess their exposure and apply vendor mitigations as a priority. The alert lists two vulnerabilities: CVE-2026-18556 and CVE-2026-18577, both rated “HIGH” with a score of 8.2.

According to the ACSC, the vulnerabilities are authentication bypass issues that may allow unauthorised access “through an alternate path or channel”. The agency said the issues affect “all current versions of N-central, including 2026.3”.

The advisory is aimed at “all Australian Managed Service Providers (MSP) and Enterprise IT organisations that utilise the N-able N-central product,” and notes that small to medium businesses should check with their MSP or IT provider to determine whether N-central is in use.

The ACSC said patches were released on 1 August 2026, and that Hotfix 2 was released on 6 August 2026. It advised organisations to upgrade to Hotfix 2 as a priority.

Recommended mitigation steps include reviewing networks for vulnerable versions, reassessing whether the N-central interface needs to be exposed to the internet, applying patches as soon as practicable, and monitoring for suspicious activity. The ACSC also noted that the vendor has released indicator of compromise (IoC) detection scripts intended to help identify compromise.

The agency said it has “no information to indicate that a specific industry or sector is being targeted.”

Organisations that have been impacted, suspect impact, or require assistance can contact the ACSC via 1300 CYBER1 (1300 292 371), according to the alert.

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.