>samit_hota
Back to security news
SN-2026-289CriticalOpen

N-able RMM Vulnerability Exploited to Grant Admin Privileges

Samit Hota·
CVE ID
CVE-2026-18577
Affected Products / Orgs
N-able RMM Servers
#news#vulnerability-disclosure#n

Threat actors are actively exploiting a newly identified patch bypass vulnerability in N-able RMM servers, tracked as CVE-2026-18577. The flaw allows unauthenticated attackers to bypass authentication controls and gain full administrator access to affected management instances.

The Vulnerability

N-able identified an alternative exploitation vector over the weekend that effectively circumvents previous security patches. Authentication bypass vulnerabilities in Remote Monitoring and Management (RMM) software often occur when administrative web endpoints fail to properly validate user sessions across alternative request routes or mishandle modified API parameters. By exploiting this flaw, an unauthenticated attacker can elevate their privileges directly to full administrator status without supplying valid credentials.

Impact and Blast Radius

RMM platforms represent some of the highest-value targets on an organization’s perimeter. Managed Service Providers (MSPs) and enterprise IT teams use RMM servers to push software updates, run privileged scripts, and manage remote endpoints across entire client estates.

Gaining administrative privileges on an N-able RMM server gives an attacker native control over the system’s management features. From this position, an attacker can push malicious payloads, drop ransomware, or execute arbitrary code across all downstream endpoints managed by that server, completely bypassing client-side endpoint detection controls.

Organizations running N-able RMM servers should immediately apply the vendor’s latest patch updates addressing CVE-2026-18577. To reduce immediate exposure:

  • Restrict administrative interface access so that management portals are not exposed directly to the public internet, enforcing access via IP whitelisting or management VPNs.
  • Audit server access logs for any unauthorized administrative log-ins or unexpected active sessions created over the weekend.
  • Review task execution logs for unusual scripts or mass commands scheduled to run across connected endpoints.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call