
On 19 August 2026 the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) issued a high alert about two vulnerabilities in N-able N-central, a tool IT providers use to manage their customers' computers remotely. The agency says it has observed the flaws being targeted within Australia. Most small businesses have never heard of N-central and will never log in to it, yet the alert speaks to them directly: ask your managed service provider or IT provider whether they use it, and whether it has been patched.
What the ACSC alert says
The ACSC alert on active exploitation of a remote monitoring and management platform carries the agency's "High" status, which it defines as a vulnerability where people should act quickly, within 48 hours. The main points are:
- The alert is relevant to all Australian managed service providers (MSPs) and enterprise IT organisations that use N-able N-central.
- The two flaws, CVE-2026-18556 and CVE-2026-18577, are authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel.
- They affect all current versions of N-central, including 2026.3.
- Patches were released at the start of August, with a second fix, Hotfix 2, on 6 August 2026. The ACSC says organisations should upgrade to Hotfix 2 as a priority.
- The ACSC has no information to indicate that a specific industry or sector is being targeted.
The alert is written for a technical audience, but one line is aimed at everyone else. In the ACSC's words, small to medium business "should engage with their MSP or Enterprise IT provider to understand if they use the N-able N-central product".
What N-able has confirmed
The vendor's own account is in N-able's security update of 10 August 2026. N-able says its monitoring service detected a threat actor exploiting a previously unknown vulnerability in a customer environment, that the flaw allowed remote administrative access without authentication, and that the intruder then used N-central's remote control feature to connect to managed devices and installed a tunnelling service on them to keep access. N-able says a limited number of customers have been identified as impacted and that its investigation is continuing. It has not published a root cause analysis yet.
| Date (2026) | What happened, according to N-able and the ACSC |
|---|---|
| 31 July | N-able detects a threat actor exploiting an unknown N-central vulnerability. |
| 1 August | N-able issues first public guidance and an upgrade recommendation. The ACSC gives this as the date patches were released. |
| 2 August | N-able's timeline lists Hotfix 1 (version 2026.3.1.7), with a mitigation applied to its hosted environments. |
| 6 August | A related attack path is found. Hotfix 2 (version 2026.3.1.10) is released the same day and supersedes Hotfix 1. |
| 10 August | N-able publishes its security update with indicators of compromise. |
| 19 August | ASD's ACSC issues its high alert after observing targeting within Australia. |
One passage in the vendor's update matters for anyone who patched late. N-able says applying Hotfix 2 closes the hole but does not remove an intruder who is already inside, and that attackers were seen creating new accounts and resetting existing ones on unpatched systems. Its advice is that anyone who applied either hotfix more than a few days after release should treat the environment as potentially compromised and review all user accounts, access privileges and activity.
Why a tool you have never used puts you at risk
Remote monitoring and management (RMM) software is how an IT provider looks after hundreds of computers without visiting each office. The ACSC describes N-central as a platform used to discover, manage, automate and secure endpoints and network infrastructure. In plain terms, it can install software, run commands and open remote sessions on every device it manages.
That makes it a master key. A builder with twelve laptops, a medical clinic's front desk and a wholesaler's warehouse terminals may all sit under one provider's management console. If that console is compromised, the customers' computers are reachable through a channel that their own firewalls and antivirus tools are set up to trust. This is what the ACSC means when it files the alert under supply chain risk.
It is worth being precise about what is not known. Neither the ACSC nor N-able has named affected organisations, and the ACSC says it has no indication that a particular sector is being singled out. Using an IT provider that runs N-central does not mean you have been breached. It means you are entitled to a clear answer about whether your provider acted in time.
What to do this week
If your business uses an outside IT provider, send these questions today and ask for written answers. They follow the mitigation advice in the ACSC alert and the actions N-able asks of its customers.
- Do you use N-able N-central to manage any of our systems? If the answer is no, ask which remote management tool they do use and how it is kept patched.
- Which version are you running, and on what date was Hotfix 2 applied? The fixed version is 2026.3.1.10. If it went on more than a few days after 6 August, ask what account and activity review has been done since.
- Is the N-central interface exposed to the internet, and does it need to be? The ACSC asks organisations to review that exposure.
- Have you run the vendor's indicator of compromise checks, and what did they find? N-able notes its detection tool only checks for known indicators, so a clean result is one layer of assurance and not proof.
- Is multi-factor authentication enforced on every account on the platform? N-able asks customers to enforce it across all accounts and to audit user access.
- How and when will you tell us if you find suspicious activity? The ACSC asks that suspicious activity be reported to it as well.
If your business runs N-central in-house, the same list applies to your own IT team: upgrade to Hotfix 2, review exposure, hunt for the published indicators and audit accounts.
Strengthen the relationship, not only the patch
The ACSC publishes two short guides that are useful well beyond this incident. Questions to ask managed service providers covers whether a provider implements the Essential Eight, administers systems securely, monitors activity, assesses its own systems for vulnerabilities and is prepared for incidents. How to manage your security when engaging a managed service provider recommends writing security expectations into the contract, including a clause that obliges the provider to notify you of any incident that may endanger your network, and limiting the provider's privileged access to what the job requires.
Comingwave is a technology company that provides managed IT support, cyber security and IT consulting to small and medium businesses. If you would like an independent review of how your systems are managed and who holds privileged access to them, ask us for a free first consultation or a written quote.
Key takeaways
- ASD's ACSC issued a high alert on 19 August 2026 after observing targeting of N-able N-central vulnerabilities within Australia.
- CVE-2026-18556 and CVE-2026-18577 are authentication bypass flaws affecting all current N-central versions, including 2026.3.
- Hotfix 2 (2026.3.1.10), released on 6 August, is the version to be on.
- Patching late is not the end of the job: N-able advises treating late-patched environments as potentially compromised and reviewing accounts.
- Small businesses should ask their IT provider whether N-central is in use and get the patch date in writing.
Frequently asked questions
What is N-able N-central?
It is a remote monitoring and management platform. Managed service providers and large IT departments use it to discover, manage, automate and secure computers and network equipment from a central console.
My business does not use N-central. Does the alert still apply to us?
It may, if your IT provider uses it to manage your devices. The ACSC specifically asks small and medium businesses to check with their provider. If no one manages your systems with N-central, this alert does not apply to you.
What do CVE-2026-18556 and CVE-2026-18577 allow an attacker to do?
The ACSC describes both as authentication bypass vulnerabilities that may allow unauthorised access through an alternate path or channel. N-able says the flaw it detected allowed remote administrative access without authentication.
Has a fix been released?
Yes. N-able released Hotfix 1 at the start of August and Hotfix 2, version 2026.3.1.10, on 6 August 2026. The ACSC advises upgrading to Hotfix 2 as a priority.
Who should we contact if we suspect a compromise?
Tell your IT provider immediately and report it to ASD's ACSC, which can be reached on 1300 CYBER1 (1300 292 371) for organisations that have been impacted or need advice.