A security flaw in N-able N-central, a remote monitoring and management platform widely used by IT service providers, is being actively exploited by attackers to take over servers.
- What it is: Attackers can bypass authentication entirely and gain full administrative control of an on-premise N-central server, without needing a username or password.
- Who is affected: Businesses whose IT is managed through an on-premise N-central deployment running version 2026.3.1 or earlier. Hosted (cloud) N-central customers have already been patched automatically by the vendor.
- What the risk is: Once inside, attackers have used the platform's remote-control features to reach every device it manages, and have installed additional tools to keep that access even after the immediate flaw is fixed.
- What action is needed: On-premise N-central deployments need to be updated to version 2026.3.1 Hotfix 1 or later as a priority.
We recommend confirming with your IT provider whether N-central is used in your environment, and if so, that it has been updated to a patched version.