Government Advisory

Urgent: Active Attacks Targeting N-able/N-central IT Management Software in Australia

ACSC · 19 Aug 2026
Key Takeaway If your business uses an IT provider or MSP, ask them immediately whether they use N-able or N-central and confirm the relevant patches have been applied.

The Australian Cyber Security Centre (ACSC) has warned that attackers are actively exploiting two vulnerabilities—CVE-2026-18556 and CVE-2026-18577—in N-able and N-central, widely used remote monitoring and management (RMM) platforms. These tools are commonly used by managed service providers (MSPs) and IT teams to remotely oversee and maintain business networks, making them an attractive target for cybercriminals seeking broad access to multiple systems at once.

Because RMM platforms often have privileged access across an organisation's IT environment, a successful compromise could allow attackers to move laterally, deploy ransomware, or steal sensitive data from any business connected through the platform. This is especially concerning for small businesses that rely on third-party IT providers or MSPs using N-able or N-central to manage their systems, as a single breach could affect many downstream clients simultaneously.

The ACSC is urging all organisations using these platforms, or any partner or MSP that uses them on their behalf, to urgently assess their exposure and apply available vendor mitigations or patches. Businesses should also review recent remote access activity for signs of unusual behaviour.

RMM security vulnerability alert ACSC MSP risk patch management

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.