Hackers Can Take Full Control of N-central Systems Without Password, National CERT Warns
Pakistan’s National Cyber Emergency Response Team has warned organisations of a critical security vulnerability in N-central, a remote management platform used to administer computers and servers, saying attackers could gain full control of affected systems without needing a password or user authorisation.
The National CERT issued an advisory after identifying a vulnerability that affects both cloud-based and on-premises deployments of N-central. The flaw could allow attackers to bypass authentication and obtain administrative control of a compromised system, potentially opening a path to other connected computers and networks.
According to the advisory, exploitation attempts targeting N-central systems had been identified up to July 31, 2026, raising concerns over the potential impact on organisations relying on the platform to remotely manage large numbers of devices.
The vulnerability is particularly serious because a successful compromise of a single N-central system could expose multiple connected machines and potentially affect several departments, offices or organisations managed through the platform.
National CERT said the latest security weakness was linked to an incomplete remediation of a previously identified vulnerability, leaving systems exposed to further exploitation.
The cyber response authority has directed organisations using N-central to immediately upgrade to the latest secure version and restrict direct internet exposure of the platform.
Organisations have also been advised to update security software on all computers connected to N-central and closely monitor their networks for suspicious activity.
National CERT further urged organisations to immediately report any suspected cyberattack or compromise to National CERT Pakistan, stressing that timely reporting is critical to limiting the spread and impact of an intrusion.
The advisory highlights the growing risks associated with remotely managed IT infrastructure, where a compromise of a central management platform can potentially turn a single security weakness into a much broader network breach.




