N-Able N-Central Exploitation Results in RMM Tool Deployment
Sophos, Tuesday, August 4th, 2026
Sophos reports attackers exploiting N-able N-central to deploy AnyDesk, TeamViewer, and TacticalRMM.
Threat actors exploited CVE-2026-18577, a critical authentication bypass in N-able's N-central remote monitoring platform, to gain privileged access to managed environments.
After compromise they deployed additional remote monitoring and management tools including AnyDesk, TeamViewer, and TacticalRMM.
They also used Cloudflare Tunnel disguised to blend with legitimate traffic.
Compromising an RMM platform is particularly damaging because it grants access to every managed downstream environment.