If a managed service provider or an outsourced IT team looks after your computers, it may be doing that through software that has been under attack for three weeks. The Australian Signals Directorate's Australian Cyber Security Centre published a high alert on Wednesday saying it has observed the targeting of vulnerabilities in N-able N-central within Australia.

N-central is a remote monitoring and management platform. Providers and large enterprise IT departments use it to discover, manage, automate and secure endpoints and network infrastructure, which means one N-central server reaches into every customer estate it administers. The customer does not pick the product and in most cases does not know it is there.

Two authentication bypass vulnerabilities are involved: CVE-2026-18556 and CVE-2026-18577. Both allow unauthorised access through an alternate path or channel, and both affect all current versions of N-central, including 2026.3. The agency says patches were released on 1 August with a second hotfix on 6 August, and that organisations should get to Hotfix 2 as a priority.

A high alert on the agency's own scale means a vulnerability where there are generally no mitigating factors available and the impact is widespread among customers, and where people should act within 48 hours. The agency says it has no information indicating a specific industry or sector is being targeted. It has not attributed the activity to a named actor or a state, and it has not said how many Australian organisations are affected.

The vendor's account of the discovery is on its own status page and blog. N-able says its Adlumin managed detection product picked up unusual activity in a customer environment on 31 July and identified a threat actor exploiting a then-unknown flaw. It registered CVE-2026-18556, shipped Hotfix 1 as build 2026.3.1.7 on 2 August, and registered CVE-2026-18577. Monitoring on 6 August found a related attack path and the company released Hotfix 2, build 2026.3.1.10, the same day.

On the company's description the attacker reached remote administrative access without authenticating, then used N-central's Take Control feature to connect to managed devices and registered Cloudflare tunnel services on them to keep access after the console was closed off. N-able says a limited number of customers have been identified as impacted, that it has contacted each of them directly, and that its investigation is still open. It has not published a count.

The indicators it published can be checked without specialist tooling. The company tells customers to look in user document folders for a file named svchost.exe, to look for a registered service called Cloudflared, and to check firewall logs for inbound connections from four listed addresses. The agency says detection scripts are available from the vendor's support page and asks organisations that find something to report it.

The United States Cybersecurity and Infrastructure Security Agency added CVE-2026-18577 to its known exploited vulnerabilities catalogue on 3 August and CVE-2026-18556 on 4 August, giving federal civilian agencies until 6 and 7 August to act. Its entry records the second flaw as the result of an incomplete patch for the first. The same product was in that catalogue almost exactly a year earlier, when a command injection flaw and an insecure deserialisation flaw in N-central were added on 13 August 2025.

The agency's advice to a small or medium business is to ask. Contact the provider, establish whether it runs N-central, and confirm it has patched and is watching for suspicious activity. For anyone running the product themselves, it asks whether the interface needs to be reachable from the internet at all.

What is known is that two bypasses exist, that both are patched, that the second existed because the first patch was incomplete, and that the agency has seen them being targeted here. What is not known is how many Australian organisations were reached, in which sectors, or by whom. The agency has asked to be told, on 1300 292 371.