Threat Response - Critical vulnerability in N-Able N-Central
Dutch follows English
A critical security vulnerability has been discovered in N-able N-central, a widely used IT management platform. Attackers can take complete control of affected systems without needing any passwords or credentials. Active exploitation has been observed in the wild, making immediate action essential. If you are hosting N-Central on-premise, make sure to update immediately.
Description
N-able N-central is a remote monitoring and management (RMM) platform used by IT service providers to manage their customers' IT infrastructure. A vulnerability has been discovered in versions earlier than 2026.3.1.14 that allows attackers to remotely execute malicious code on the system without any form of authentication. This means an attacker can gain complete control over the N-central server simply by sending specially crafted requests over the internet.
Impact
We estimate the impact of this vulnerability as high. The vulnerability has received the maximum severity score of 10.0 out of 10.0 (CVSS v4). If exploited, attackers can take complete control of your N-central management server and potentially access and compromise all systems managed through N-central. Because N-central typically manages many other systems, a single compromise can cascade across your entire IT infrastructure.
Risk
We estimate the risk of this vulnerability as high. N-able has confirmed that attackers are actively attempting to exploit this vulnerability in the wild. N-central systems are typically accessible from the internet, making them easy targets. No special skills or credentials are required to exploit this flaw, which significantly increases the likelihood of successful attacks.
Mitigation
N-able has released security updates [2] to address this vulnerability:
- For on-premises installations: Upgrade to N-central version 2026.3 HF4 immediately
- For hosted/cloud installations (NCOD): N-able has already applied the patches; verify with your provider that your instance is updated
What should you do?
- Identify if you use N-able N-central in your environment (either on-premises or hosted)
- Update immediately if you run an on-premises installation, upgrade to version 2026.3 HF4
- Verify with your service provider if you use a hosted N-central instance that patches have been applied
- Investigate your environment for indicators of compromise following N-able's guidance [3]
- Review which systems have external access to your N-central instance and restrict where possible
- Contact Northwave if you need assistance with updates, investigation, or have questions
What will Northwave do?
We will continue to monitor your environment for any suspicious activity related to this vulnerability. We will monitor any developments regarding this vulnerability. If new critical information about this threat arises we will reach out to you. You can call us by phone or send us an email if you would like additional information.
E-mail: soc@northwave-cybersecurity.com
Do you have an incident right now? Call our Incident Response Team: 00800 1744 0000
Disclaimer applies, see below.
Sources
[1]: https://advisories.ncsc.nl/2026/ncsc-2026-0342.html
[2]: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm
[3]: https://www.n-able.com/blog/n-central-security-hotfix-september-5-2026
Er is een kritieke beveiligingskwetsbaarheid ontdekt in N-able N-central, een veelgebruikt IT-beheerplatform. Aanvallers kunnen de volledige controle over getroffen systemen overnemen zonder wachtwoorden of andere inloggegevens nodig te hebben. Er zijn actieve aanvallen in het wild waargenomen, waardoor directe actie noodzakelijk is. Als u N-central lokaal (on-premises) host, zorg er dan voor dat u onmiddellijk een update uitvoert.
Beschrijving
N-able N-central is een platform voor remote monitoring en management (RMM) dat door IT-dienstverleners wordt gebruikt om de IT-infrastructuur van hun klanten te beheren. Er is een kwetsbaarheid ontdekt in versies ouder dan 2026.3.1.14 waarmee aanvallers op afstand kwaadaardige code kunnen uitvoeren zonder enige vorm van authenticatie. Dit betekent dat een aanvaller volledige controle over de N-central-server kan krijgen door speciaal opgestelde verzoeken via internet te versturen.
Impact
Wij schatten de impact van deze kwetsbaarheid als hoog in. De kwetsbaarheid heeft de maximale score van 10,0 op 10,0 (CVSS v4) gekregen. Als deze kwetsbaarheid wordt misbruikt, kunnen aanvallers de volledige controle over uw N-central-beheerserver overnemen en mogelijk toegang krijgen tot en compromitteren van alle systemen die via N-central worden beheerd. Omdat N-central doorgaans veel andere systemen beheert, kan één succesvolle aanval zich verspreiden naar uw volledige IT-infrastructuur.
Risico
Wij schatten het risico van deze kwetsbaarheid als hoog in. N-able heeft bevestigd dat aanvallers actief proberen deze kwetsbaarheid te misbruiken. N-central-systemen zijn meestal via internet bereikbaar en daardoor aantrekkelijke doelwitten. Er zijn geen speciale vaardigheden of inloggegevens nodig om deze kwetsbaarheid uit te buiten, wat de kans op succesvolle aanvallen aanzienlijk vergroot.
Mitigatie
N-able heeft beveiligingsupdates uitgebracht [2] om deze kwetsbaarheid te verhelpen:
- Voor on-premises installaties: Upgrade onmiddellijk naar N-central versie 2026.3 HF4.
- Voor gehoste/cloudinstallaties (NCOD): N-able heeft de patches al toegepast. Controleer bij uw leverancier of uw omgeving is bijgewerkt.
Na het uitvoeren van de update adviseert N-able nadrukkelijk om uw systemen te onderzoeken op mogelijke tekenen van een inbraak aan de hand van de gepubliceerde Indicators of Compromise (IoC's). Zie hiervoor [3].
Wat moet u doen?
- Controleer of u N-able N-central gebruikt binnen uw omgeving (lokaal of gehost).
- Werk direct bij als u een on-premises installatie gebruikt en upgrade naar versie 2026.3 HF4.
- Bevestig bij uw dienstverlener dat de patches zijn toegepast als u een gehoste N-central-omgeving gebruikt.
- Onderzoek uw omgeving op Indicators of Compromise volgens de richtlijnen van N-able [3].
- Controleer welke systemen externe toegang hebben tot uw N-central-omgeving en beperk deze toegang waar mogelijk.
- Neem contact op met Northwave als u hulp nodig heeft bij updates, onderzoek of als u vragen heeft.
Wat doet Northwave?
Wij blijven uw omgeving monitoren op verdachte activiteiten die verband houden met deze kwetsbaarheid. Northwave houdt de ontwikkelingen omtrent deze kwetsbaarheid in de gaten. Als er belangrijke nieuwe informatie omtrent deze dreiging bekend wordt, stellen wij u hiervan op de hoogte. Als u behoefte heeft aan extra informatie zijn we zowel telefonisch als via email bereikbaar.
E-mail: soc@northwave-cybersecurity.com
Heeft u nu een incident? Bel ons Incident Response Team: 00800 1744 0000
Disclaimer is van toepassing, zie onder.
Bronnen
[1]: https://advisories.ncsc.nl/2026/ncsc-2026-0342.html
[2]: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF4_Release_Notes.htm
[3]: https://www.n-able.com/blog/n-central-security-hotfix-september-5-2026

