← All regulatory updates

New York State Department of Financial Services · NY

Cybersecurity Alert - N-central Vulnerability Affecting Some Managed Service Providers

August 11, 2026

Summary

NY DFS issued an alert to all regulated entities about an active campaign exploiting vulnerabilities (CVE-2026-18556, CVE-2026-18577) in N-able's N-central RMM tool, which is used by some managed service providers. Regulated entities must determine whether N-central is in use by themselves or their third-party service providers, work with those providers to assess and mitigate exposure, and ensure any cybersecurity incidents are reported to DFS per 23 NYCRR § 500.17.

AI-generated summary · Aug 29, 2026. Verify with your compliance counsel before acting.

How this was generated

We record the exact prompt, model, and output for every AI response so it can be audited for accuracy.

Industry Letter


Date: August 11, 2026

To: All DFS-Regulated Entities

Re: Cybersecurity Threat Alert – N-central Vulnerability

The New York State Department of Financial Services (“DFS” or “Department”) is issuing this alert to DFS-regulated entities regarding an active cybersecurity campaign targeting a security vulnerability in the remote monitoring and management system N-central, developed and maintained by N-able (“Alert”). N-central is used by some managed service providers (“MSPs”) to centrally monitor, patch, and remotely access their customers’ services and endpoints (also referred to as Remote Monitoring and Management services or RMM services).

Threat actors are targeting a Known Exploited Vulnerability in N-central to compromise MSP environments. Once access is obtained, threat actors may create or register for new services, allowing continued access even after compromised N-central credentials are revoked. Attackers are using a compromised MSP’s environment to move laterally into their customer’s networks and information systems with administrator network privileges.

DFS-regulated entities should promptly determine whether N-central is used within their environment or by any MSP or other Third-Party Service Provider that supports their information systems. Where N-central is used, DFS-regulated entities should work with their service providers to assess and mitigate potential exposure, including reviewing N-central activity for evidence of unauthorized or persistent access; verifying that applicable security updates, including software patches and other threat mitigation steps, have been implemented; and evaluating whether any systems or credentials were affected.

While the vulnerability addressed in this Alert is likely limited to MSPs, the senior governing bodies and senior officers of DFS-regulated entities must actively engage in cybersecurity risk management, including through monitoring and oversight of third-party service providers. To that end, the Department expects DFS-regulated entities that may be exposed to cybersecurity risk related to the N-central vulnerability to appropriately manage this risk through due diligence and engagement with Third-Party Service Providers on this issue. Additionally, DFS-regulated entities should ensure that they continue to report all Cybersecurity Incidents to DFS, including those originating at Third-Party Service Providers, as required by 23 NYCRR § 500.17.

Additional Resources:

For more information about compliance with the DFS Cybersecurity Regulation, visit DFS’s Cybersecurity Resource Center.

Source: https://www.dfs.ny.gov/industry-guidance/industry-letters/il20260811-cyber-threat-alert-n-central

Common questions

What does "Cybersecurity Alert - N-central Vulnerability Affecting Some Managed Service Providers" cover?
NY DFS issued an alert to all regulated entities about an active campaign exploiting vulnerabilities (CVE-2026-18556, CVE-2026-18577) in N-able's…
Which agency issued this update?
This update was issued by New York State Department of Financial Services.
When was it published?
It was published on August 11, 2026.

Related updates

Stop missing the rule that costs you a loan.

Cybersecurity Alert - N-central Vulnerability Affecting Some Managed Service Providers — Reglith