Criminals can get into company computers remotely: what is happening with N-able
Imagine giving the keys to your house to a company so it can watch over it while you travel. That company keeps a copy of all its clients’ keys stored in its office. Now imagine a thief discovers a way to get into that office without anyone noticing and steals the whole keyring. Something similar to this is what is happening with a program called N-able.
This program is a tool widely used by IT companies to take care of other companies’ computers remotely. It is like a plumber being able to enter your house with an app to fix the boiler without being physically there. Well, some cybercriminals have found a crack in that program that lets them slip in and take control of many companies’ computers without permission.
What exactly has happened
Computer security experts have discovered that attackers are taking advantage of a flaw in a part of the program called N-central. This flaw has an identification number: CVE-2026-18577. You do not need to remember it. What matters is that it is serious. On the scale technicians use to measure how dangerous a flaw is (from 0 to 10), this one scores 8.2. It is a very high mark, like a very serious failure in an exam.
What do criminals get with that flaw? Basically, they impersonate the system administrators. That is, they get the permissions of the person in charge of managing the program, as if they stole the security chief’s ID card. Once inside, they can use a function called “Take Control” to connect to the computers of the companies that use this service.
The most worrying thing is that the attackers have looked for a way to stay inside for a long time. They have created a secret passageway (a “tunnel”) to be able to come back again and again, even after the company tries to close the door on them. It is like if, on top of stealing, they installed a back door in your house to be able to come back whenever they want.
Who this affects
This problem affects companies that use N-able to take care of their computers. Specifically, those that have a version of the program before 2026.3.1.7. The good news is that the company N-able has already released an update to fix the hole. If you have a company computer that uses it, the IT technicians are probably already working on updating it. The recommended update is version 2026.3.1.10.
You may wonder: «and what do I care? I am not a company». Well, it matters to you more than you think. Many of the companies where we work, shop or deal with every day use programs like this to manage their computers. If a thief gets into the company’s program, they can access customer data, emails and documents. That can end up affecting your personal information without you knowing.
What you can do
You cannot fix the program on your own. But you can do three simple things that protect you even if a company suffers an attack:
- Do not reuse the same password on several sites. If criminals steal one, do not let it work to get into all your accounts.
- Enable two-step verification on your important accounts (the bank, email). It is a system that asks for an extra code, on top of your password, to confirm it is you. It is like a second lock on the door.
- Keep updates up to date. When your computer or mobile asks you to update, do not leave it for later. An update is like a vaccine for the program: it fixes the holes the thieves could slip through.
The moral of the story
This news reminds us that, in the digital world, we entrust a lot of our lives to programs we cannot see. The companies that store our data have the obligation to keep it well locked. And we, for our part, can do a lot with small gestures: different passwords, double verification and always updating. They are the three locks you do control.
The technicians are working to plug the hole and check whether any client has been affected. In the meantime, this story is a good reminder of why computer security concerns us all, even if we do not work in an IT office.






