Home / Uncategorized / Attack on N-able: the hole in the tool technicians use to fix your computer from afar

Attack on N-able: the hole in the tool technicians use to fix your computer from afar

Cybercriminals have found an open door in a very special program. It is called N-central and it is used by IT technicians. With it they can fix your computer without leaving their office. On Saturday 8 August, the company that makes it, N-able, launched an urgent update. Reason: some attackers were exploiting the flaw to sneak into company computers. We’ll tell you what happened and why it matters to you, even if you are not an IT person.

What is N-central and why is it so important?

Imagine your computer breaks down. A technician could come to your home. But that costs time and money. With N-central, the technician connects to your machine over the internet, as if they picked up the TV remote control. They see it, fix it and done. Many IT companies use this tool to serve their clients without travelling.

Now comes the important part: if a thief manages to get into the technician’s program, they can reach all the computers that technician manages. It is as if someone stole the master key of an entire building with a single copy. That is why a flaw in this tool is much more serious than a flaw in a normal program.

What exactly happened?

N-able has discovered a security flaw in N-central. A security flaw is like a broken lock: it lets in someone who should not. What is worrying is that the attackers were already using it before the company realized it.

The flaw has a code name: CVE-2026-18577. You do not need to remember it. What matters is its severity. Experts score flaws from zero to ten, like school grades. This one gets an 8.2. That is, very dangerous, almost a ten.

With that hole, the attackers could pass themselves off as administrators. That is, they could give orders inside the system, as if they were the bosses. In addition, they could use a function called “Take Control”, which means taking control. It is the same one the technician uses to fix your machine, but in the hands of the thieves.

And there is a more unsettling detail. The attackers left themselves a secret door to get back in, even after the company cut off their access. It is as if a thief, after the lock is changed, had left a window open just in case.

Who does it affect?

The flaw affects versions of N-central before 2026.3.1.7. N-able says the number of affected clients is limited. Even so, it recommends updating now to version 2026.3.1.10.

And you? If your IT company uses N-able, you cannot fix it yourself. But you can ask. A good question is: “Do you have everything updated?”. Serious companies will take it into account and thank you for it.

The update is like a vaccine

You may find “update your program” boring. But think of it as a vaccine. The vaccine does not cure you: it protects you from a virus that could come. The update works the same way. It closes the hole through which an attacker could sneak in.

That is why, when a program asks you to update, do not leave it for tomorrow. Do it. And if you ever receive a notice from a company you work with asking you to update something, take it seriously. It is not an annoyance: it is protection.

What you can do

You do not need to be an IT person to protect yourself. Three simple gestures are enough:

  • Keep your devices updated: computer, phone and tablet. Updates plug the holes thieves get in through.
  • Distrust strange calls or messages that ask for data. Criminals also trick you by phone, pretending to be technicians or your bank.
  • If you work with an IT company, ask about its security. It is a normal question, not an offence.

The N-able news is another reminder that nobody is free from risk. But most scares are avoided with two very simple gestures: updating and being distrustful. Now you know what this news means and why it affects you. Share it with anyone who has a company or works with IT technicians: it can save them a nasty scare.