HomeBlogsACSC High Alert: Active Exploitation of N-able N-central RMM Platform Targeting Australian Organisations

ACSC High Alert: Active Exploitation of N-able N-central RMM Platform Targeting Australian Organisations

Updated: August 26, 2026|4.2 min read
ACSC High Alert: Active Exploitation of N-able N-central RMM Platform Targeting Australian Organisations

Australia's cyber security agency issued a High Alert on 19 August 2026 confirming active exploitation of vulnerabilities in N-able N-central, a remote monitoring and management platform used by managed service providers and enterprise IT teams across the country. The advisory came with a clear instruction: assess your exposure and apply vendor mitigations as a priority.

ACSC High Alert: Active Exploitation of N-able N-central RMM Platform

This is a live threat. It is not a theoretical risk or a future concern. The ASD's Australian Cyber Security Centre observed targeting of these vulnerabilities inside Australia before issuing the alert. Organisations running N-central need to act on this today.

ASD ACSC Threat Advisory Live Warning

What the ACSC Alert Says

Two vulnerabilities are confirmed: CVE-2026-18556 and CVE-2026-18577. Both carry a CVSS score of 8.2, rated HIGH. According to the ACSC advisory, both are authentication bypass issues that may allow unauthorised access through an alternate path or channel.

In plain terms: an attacker does not need a valid username or password to gain access. The authentication step can be bypassed entirely. The ACSC confirmed that all current versions of N-central are affected, including the most recent version 2026.3.

Patches were released on 1 August 2026. Hotfix 2 was released on 6 August 2026. The ACSC advises organisations to upgrade to Hotfix 2 as a priority.

The advisory is directed at all Australian MSPs and enterprise IT organisations using N-able N-central. It also specifically notes that small to medium businesses should check with their MSP or IT provider to confirm whether N-central is in use on their behalf. This is a supply chain signal thought worth taking seriously.

ACSC Alert N-able N-central Active Exploitation

Why RMM Vulnerabilities Carry Outsized Risk

N-central is not a standard business application. It is the platform MSPs use to remotely access, manage, monitor, and automate systems across their entire client base. A compromised RMM platform is a key to every lock the MSP manages.

One authentication bypass in one MSP's N-central instance can translate to access across dozens or hundreds of client environments. The attacker does not need to target each downstream customer separately. They access the management layer and move from there.

The ACSC advisory notes no specific industry is being targeted. That observation cuts both ways. Opportunistic exploitation of authentication bypass vulnerabilities does not discriminate by sector. Any internet-facing N-central instance running a version prior to Hotfix 2 is a potential entry.

For organisations managed by an external MSP, one question is worth asking directly today: does your provider use N-central, and have they applied Hotfix 2?

This is exactly the kind of third-party supply chain risk that penetration testing for MSP environments is designed to surface. The vulnerability lives in your provider's platform, not your own, but the exposure is yours.

MSP Supply Chain Vulnerability Risks

The ACSC's Specific Mitigation Steps

The advisory lists four recommended actions for organisations running N-central. These are not suggestions. They are the ACSC's direct guidance in response to confirmed, active exploitation.

First: review networks and environments for vulnerable versions of N-central. If any instance is running a version prior to Hotfix 2, it should be treated as potentially compromised until updated and confirmed clean.

Second: reassess whether the N-central interface needs to be exposed to the internet. RMM platforms rarely need to be publicly accessible. Restricting access to known IP ranges or requiring VPN access before the management interface is reachable reduces the exploitable attack surface immediately.

Third: apply patches as soon as practicable. Hotfix 2 was released on 6 August 2026. The patches have been available for two weeks. Any instance still running a vulnerable version at this point has had two weeks of exposure against a known authentication bypass with a CVSS score of 8.2.

Fourth: monitor for suspicious activity. The ACSC specifically noted that N-able has released indicator of compromise detection scripts to help organisations identify whether a compromise has already occurred. Running these scripts before assuming a clean state is the right approach. Patching after a compromise does not undo the access that already occurred.

For any organisation that suspects impact, the ACSC contact line is 1300 CYBER1 (1300 292 371).

What am I risking by not acting?

Your Last Pentest Is Already Out of Date

Every week you ship without continuous testing is a week a vulnerability goes unseen. See what Capture The Bug finds in your first engagement.

What This Reveals About the Broader Exposure Problem

Hotfix 2 was released on 6 August 2026. The Australian Essential Eight Maturity Level 3 requires critical patches for internet-facing services within 48 hours. Maturity Level 2 requires within two weeks. That two-week window closed on 20 August. Organisations at any Essential Eight maturity target that have not applied this patch are now outside their own stated requirements.

The supply chain dimension is the part most organisations will underestimate. If your business relies on an MSP, your security posture is partly determined by your provider's patch discipline and whether their own infrastructure has been validated. The ACSC's explicit note that SMBs should check with their provider reflects the downstream risk a compromised MSP platform creates.

This is not the first time an RMM platform has been the entry point for a wide-impact campaign. The attack surface MSPs create, a single bypass giving access to hundreds of managed environments, is among the most structurally attractive targets in the current threat landscape.

As detailed in the analysis of how attackers discover unpatched assets across cloud and SaaS environments, internet-facing management platforms are indexed and scanned continuously. An authentication bypass at CVSS 8.2 on a known RMM platform does not stay quiet. The scanning begins as soon as the CVE is public, often before most affected organisations know the advisory exists.

The question for any Australian MSP or enterprise IT team running N-central is no longer whether this vulnerability is real. The ACSC has confirmed it is being actively exploited in Australia. The question is whether Hotfix 2 is applied, whether the management interface is appropriately restricted, and whether the IoC scripts have been run.

If you have confirmed compromise or need an independent assessment of your exposure, book a consultation with Capture The Bug to scope a rapid security review.

Vulnerability Mitigation and Patch Assessment
Plan Security Better

Plan Your Annual Pentesting Strategy the Right Way

Learn how modern SaaS companies structure pentesting across the year to reduce risk, stay compliant, and avoid last-minute panic before audits.

FAQ

What are CVE-2026-18556 and CVE-2026-18577?

Both are authentication bypass vulnerabilities in N-able N-central, a remote monitoring and management platform. Both carry a CVSS score of 8.2, rated HIGH. According to ASD's ACSC, they may allow unauthorised access through an alternate path or channel, meaning an attacker does not need valid credentials to gain access. All current versions of N-central including version 2026.3 are affected.

What should Australian MSPs and IT teams do right now?

The ACSC recommends four immediate steps: review all environments for vulnerable versions of N-central, reassess whether the management interface needs to be internet-facing, apply Hotfix 2 released on 6 August 2026, and run the vendor-released indicator of compromise detection scripts to check for existing compromise before assuming a clean state.

Why is an RMM platform vulnerability particularly dangerous?

RMM platforms like N-central give MSPs remote access to their entire client base. A single authentication bypass in one MSP's platform can translate to access across dozens or hundreds of downstream customer environments. Attackers do not need to separately target each client. They compromise the management layer and move from there.

My business uses an MSP. What should I do?

The ACSC advisory explicitly directs small and medium businesses to check with their MSP or IT provider to confirm whether N-central is in use and whether Hotfix 2 has been applied. This is a supply chain risk question your provider should be able to answer immediately. If they cannot confirm the patch status, treat that as a priority concern.

Does the Essential Eight require organisations to patch this quickly?

Yes. Australian Essential Eight Maturity Level 3 requires critical patches for internet-facing services to be applied within 48 hours of release. Maturity Level 2 requires application within two weeks. Hotfix 2 was released on 6 August 2026. Organisations at any Essential Eight maturity target that have not yet applied this patch are outside their own stated requirements.

Jitendra Kumar Singh

Jitendra Kumar Singh

Associate Director & Pentester • eWPTX

Cybersecurity professional & pentester | Associate Director @ CaptureTheBug | Securing web, APIs & networks one vulnerability at a time.

- 07 / RESOURCES

Read Industry Insights

Security that works like you do.

Flexible, scalable PTaaS for modern product teams.