RMM

N-able N-central

N-able N-central is a remote monitoring and management (RMM) platform used by MSPs and IT teams. The platform supports remote commands, scripts, software deployment, file transfer and remote control. Its classic agents operate alongside the newer MSP Agent on Windows, Linux and macOS; optional Take Control components provide remote access. CISA added CVE-2026-86218, a static code injection flaw in the N-central server, to its Known Exploited Vulnerabilities catalog on 2026-09-08.

Tool overview

Category
RMM
Research authors
Liran Ravich, Cribl
Created
2026-10-01
Last modified
2026-10-05
Privileges
Windows tasks can use LocalSystem, device or custom credentials
Free / availability
No
Verification required
Not recorded
Supported platforms
LinuxWindowsmacOS

Capabilities

Remote command executionScriptingSoftware deploymentFile transferRemote control

Known vulnerabilities

  • CVE-2026-86218

Executables & installation paths

Filename
Not recorded
OriginalFileName
Not recorded
Description
Not recorded

Installation paths

C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\*
C:\Program Files (x86)\Msp Agent\*
C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe
AgentMaint.exe
AgentMonitor.exe
BASupTSHelper.exe
msp-agent-core.exe
/opt/msp-agent/*
/Library/MspAgent/*

FORENSIC EVIDENCE

Disk artifacts

File
C:\Program Files (x86)\N-able Technologies\Windows Agent\bin\agent.exe
Description
Classic Windows agent executable
OS
Windows
File
C:\Program Files (x86)\Msp Agent\msp-agent-core.exe
Description
Modern MSP Agent executable
OS
Windows
File
/opt/msp-agent/*
Description
Modern MSP Agent installation directory; Linux process name is msp-agent-core
OS
Linux
File
/Library/MspAgent/*
Description
Modern MSP Agent installation directory
OS
macOS

FORENSIC EVIDENCE

Network artifacts

Description
N-central software distribution metadata
Domains
  • sis.n-able.com
Ports
  • 80
  • 443
  • 8443
Description
N-central software updates and release feeds
Domains
  • update.n-able.com
  • releases.n-able.com
  • feeds.n-able.com
Ports
  • 443
Description
Modern MSP Agent cloud configuration, components and event delivery; shared N-able services
Domains
  • *.prd.cdo.system-monitor.com
  • eb.eu-west-1.prd.davinci.system-monitor.com
  • eb.us-west-2.prd.davinci.system-monitor.com
  • eb.ap-southeast-2.prd.davinci.system-monitor.com
  • eb.eu-central-1.prd.davinci.system-monitor.com
Ports
  • 443
Description
Vendor-assigned AWS IoT endpoints; N-central firewall documentation lists TCP 8088 for modern agent communication
Domains
  • a33d8yamkwy4nx-ats.iot.eu-west-1.amazonaws.com
  • a33d8yamkwy4nx-ats.iot.us-west-2.amazonaws.com
  • a33d8yamkwy4nx-ats.iot.eu-central-1.amazonaws.com
  • a33d8yamkwy4nx-ats.iot.ap-southeast-2.amazonaws.com
Ports
  • 8088
Description
Optional Take Control remote access infrastructure, shared with other N-able products
Domains
  • swi-rc.cdn-sw.net
  • comserver.global.mspa.n-able.com
  • comserver.us1.mspa.n-able.com
  • comserver.us2.mspa.n-able.com
  • comserver.eu1.mspa.n-able.com
Ports
  • 443
Description
Classic agents connect to an operator-specific N-central server; addresses vary by deployment
Domains
Not recorded
Ports
  • 80
  • 443

FORENSIC EVIDENCE

Other artifacts

Type
WindowsService
Value
Windows Agent Service; Windows Agent Maintenance Service (classic agent)
Type
WindowsService
Value
MSPAgent (display name MSP Agent)
Type
LinuxService
Value
MspAgent.service (systemd)
Type
macOSDaemon
Value
MspAgent (package com.n-able.mspagent)

Detections

Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/n-able_n-central_network_sigma.yml
Description
Detects potential network activity of N-able N-central RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/n-able_n-central_files_sigma.yml
Description
Detects potential files activity of N-able N-central RMM tool
Sigma
https://github.com/magicsword-io/LOLRMM/blob/main/detections/sigma/n-able_n-central_processes_sigma.yml
Description
Detects potential processes activity of N-able N-central RMM tool

References

Acknowledgements

Person
Liran Ravich
Handle
Not recorded