N-able patches exploited N-central authentication bypass CVE-2026-18577 after attackers took over managed servers

N-able says attackers exploited a flaw in its N-central remote monitoring and management platform to gain administrator access and pivot into customer-managed systems. The issue, CVE-2026-18577, affects N-central versions before 2026.3.1.7 in both on-premises and cloud-hosted deployments and is described as a new patch-bypass method for the earlier flaw CVE-2026-18556. N-able said attackers abused the Take Control remote-access feature and in some cases set up Cloudflare tunnels for persistence.
Why it matters: Managed service providers and their customers can lose control of many endpoints at once if an N-central server is compromised, making this especially urgent. Organizations using N-central should patch immediately, review the published indicators of compromise, and check for unauthorized remote sessions, scripts, accounts, and Cloudflare tunnel services.

Sources

New StormEncryptor ransomware used by former Medusa affiliate
Bill Toulas 2026.08.10 87% relevant
This article adds attribution and follow-on impact to the same underlying event around exploitation of N-central CVE-2026-18577, saying Microsoft tracks the actor as Storm-1175 and that the flaw likely preceded rapid data theft and deployment of the new StormEncryptor ransomware.
China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns
2026.08.10 98% relevant
This article directly updates the same CVE-2026-18577 N-central event, adding Microsoft's attribution of the activity to China-linked Storm-1175, the new StormEncryptor ransomware deployment starting August 2, prior Medusa use, rapid time-to-encryption, and the downstream MSP/customer blast-radius details alongside patch-bypass and exposure context.
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
info@thehackernews.com (The Hacker News) 2026.08.08 98% relevant
This article appears to update the same N-central exploitation event by reporting Hotfix 2, confirming attackers reached managed systems and established persistence beyond the initial authentication-bypass disclosure.
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
2026.08.07 97% relevant
This directly updates the same CVE-2026-18577 incident by adding that N-able confirmed attackers used N-central's Take Control feature to reach customer networks, established persistence with Cloudflare Tunnel, and that all on-prem N-central customers must now apply a second mandatory hotfix (2026.3.1.10), even if they already installed the first fix.
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
Ionut Ilascu 2026.08.05 70% relevant
This article updates the same N-central exploitation story by noting CISA has now added the flaw to KEV and imposed a three-day federal mitigation deadline, while also describing continued exploitation after an insufficient earlier fix and the emergency hotfix.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
Ionut Arghire 2026.08.05 98% relevant
This directly matches the N-central exploitation story by adding that CISA has now placed both CVE-2026-18556 and the patch-bypass CVE-2026-18577 in KEV, reinforcing that attackers used the bug chain to gain admin access to managed systems.
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
info@thehackernews.com (The Hacker News) 2026.08.05 86% relevant
The article also updates the existing N-central story by noting that CISA has now flagged CVE-2026-18577 as actively exploited, increasing urgency for organizations using N-able's remote management platform.
Feds get 3 days to patch N-able God mode flaw under active exploit
2026.08.04 96% relevant
This article updates the same underlying event by adding that CISA has now added CVE-2026-18577 to the KEV catalog with an August 6 deadline for federal agencies, and includes Huntress details that attackers used the flaw to pivot into managed endpoints and establish persistence through Cloudflare tunnels.
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
info@thehackernews.com (The Hacker News) 2026.08.04 96% relevant
This appears to update the same underlying event by adding that CISA has now placed CVE-2026-18577 in the Known Exploited Vulnerabilities catalog after evidence of customer compromises, increasing urgency and formal federal prioritization.
CVE-2026-18556 / CVE-2026-18577: N-able N-central Authentication Bypass Vulnerabilities Require Immediate Patching
Arctic Wolf Labs 2026.08.03 97% relevant
This article covers the same underlying N-able N-central exploitation event and adds concrete defender details: both CVE-2026-18556 and CVE-2026-18577 are being exploited, N-able's hotfix version is 2026.3.1.7, and observed post-compromise activity includes Cloudflare tunnels, suspicious executables, and abuse of Take Control for persistence and remote access.
N-able warns of N-central auth bypass flaw exploited in attacks
Bill Toulas 2026.08.03 98% relevant
This article is the same underlying event: N-able warning that CVE-2026-18577 in N-central is being actively exploited and urging customers to apply hotfix 2026.3.1.7. It adds details that the flaw affects hosted and on-premises deployments, is an incomplete fix for CVE-2026-18576, and includes vendor-supplied indicators of compromise such as specific IPs and abuse of Cloudflared.
N‑able Patches Vulnerability Exploited to Hack N-central Servers
Eduard Kovacs 2026.08.03 100% relevant
This article establishes a new tracked event: active exploitation of N-able N-central CVE-2026-18577, a patch-bypass authentication bypass affecting MSP remote-management infrastructure.
← Back to all stories