CVE-2026-18577 is an authentication bypass in N-central, N-able's RMM platform — the kind of box an MSP uses to reach every customer endpoint it manages. Attackers are already using it. Huntress confirmed live exploitation, and by the time the reporting landed more than half of the exposed cloud servers it could see were still on a vulnerable build. Once inside, the intruders reached managed endpoints through Take Control and registered Cloudflare tunnels as services, so their access survives a reboot. The uncomfortable part is the history. The original flaw, CVE-2026-18556, was supposedly fixed in the 2026.2 line — then someone found another way to hit the same weakness, which is what CVE-2026-18577 tracks, and the affected range grew to every build before 2026.3.1.7. That patch shipped Saturday. If you run N-central, upgrade now and assume compromise on anything that was internet-facing before you did.