ACSC alerts Australian MSPs about exploitation of N-able N-central

By William Maher on Aug 20, 2026 5:08PM
ACSC alerts Australian MSPs about exploitation of N-able N-central

An alert about active exploitation in Australia of vulnerabilities affecting N-able N-central was published by the Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC) on August 19.

The ACSC’s alert concerns two authentication bypass vulnerabilities that “may allow unauthorised access through an alternate path or channel," according to the ACSC.

At the time of the alert, it stated that the vulnerabilities affected all current versions of N-central.

The alert follows N-able’s detection on July 31 of “unusual activity inside a customer environment and identified a threat actor actively exploiting a previously unknown vulnerability in N‑central,” according to an N-able blog post dated August 10.

The attack exploited a “previously unknown” vulnerability in N‑central that allowed remote administrative access without authentication.

The attacker used N‑central’s Take Control feature to connect to managed devices, and registered Cloudflare tunnel services on those devices to maintain persistence even after their access to N‑central was revoked.

The post states the company published public guidance on August 1, then released a hotfix 1, deployed mitigation to hosted environments and notified customers on August 2. Another hotfix was released and deployed on August 6.

“A limited number of customers have been identified as impacted, and our team has directly engaged with each of them,” it states.

The blog post includes instructions and links to resources, including status and updates.

N-able’s investigation, hardening and direct customer support is continuing, N-able's August 10 post states.

Desire for more detail

Some of N-able’s post was dedicated to addressing a "desire for more detail".

Regarding “technical details and commentary circulating from third parties,” N-able stated: “We understand that can be frustrating when it feels like others are saying more than we are.”

In the post, the company said its focus was on providing facts needed to protect environments, not on speculation.

Sharing unconfirmed details could “give threat actors useful information and create confusion that makes it harder, not easier, for you to respond,” N-able stated.

The company said a “full root cause analysis is coming, and we will share it as soon as it is safe to do so." 

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?