N-able says attackers exploited a flaw in its N-central remote monitoring and management platform to gain administrator access and pivot into customer-managed systems. The issue, CVE-2026-18577, affects N-central versions before 2026.3.1.7 in both on-premises and cloud-hosted deployments and is described as a new patch-bypass method for the earlier flaw CVE-2026-18556. N-able said attackers abused the Take Control remote-access feature and in some cases set up Cloudflare tunnels for persistence.
Bill Toulas
2026.08.10
87% relevant
This article adds attribution and follow-on impact to the same underlying event around exploitation of N-central CVE-2026-18577, saying Microsoft tracks the actor as Storm-1175 and that the flaw likely preceded rapid data theft and deployment of the new StormEncryptor ransomware.
2026.08.10
98% relevant
This article directly updates the same CVE-2026-18577 N-central event, adding Microsoft's attribution of the activity to China-linked Storm-1175, the new StormEncryptor ransomware deployment starting August 2, prior Medusa use, rapid time-to-encryption, and the downstream MSP/customer blast-radius details alongside patch-bypass and exposure context.
info@thehackernews.com (The Hacker News)
2026.08.08
98% relevant
This article appears to update the same N-central exploitation event by reporting Hotfix 2, confirming attackers reached managed systems and established persistence beyond the initial authentication-bypass disclosure.
2026.08.07
97% relevant
This directly updates the same CVE-2026-18577 incident by adding that N-able confirmed attackers used N-central's Take Control feature to reach customer networks, established persistence with Cloudflare Tunnel, and that all on-prem N-central customers must now apply a second mandatory hotfix (2026.3.1.10), even if they already installed the first fix.
Ionut Ilascu
2026.08.05
70% relevant
This article updates the same N-central exploitation story by noting CISA has now added the flaw to KEV and imposed a three-day federal mitigation deadline, while also describing continued exploitation after an insufficient earlier fix and the emergency hotfix.
Ionut Arghire
2026.08.05
98% relevant
This directly matches the N-central exploitation story by adding that CISA has now placed both CVE-2026-18556 and the patch-bypass CVE-2026-18577 in KEV, reinforcing that attackers used the bug chain to gain admin access to managed systems.
info@thehackernews.com (The Hacker News)
2026.08.05
86% relevant
The article also updates the existing N-central story by noting that CISA has now flagged CVE-2026-18577 as actively exploited, increasing urgency for organizations using N-able's remote management platform.
2026.08.04
96% relevant
This article updates the same underlying event by adding that CISA has now added CVE-2026-18577 to the KEV catalog with an August 6 deadline for federal agencies, and includes Huntress details that attackers used the flaw to pivot into managed endpoints and establish persistence through Cloudflare tunnels.
info@thehackernews.com (The Hacker News)
2026.08.04
96% relevant
This appears to update the same underlying event by adding that CISA has now placed CVE-2026-18577 in the Known Exploited Vulnerabilities catalog after evidence of customer compromises, increasing urgency and formal federal prioritization.
Arctic Wolf Labs
2026.08.03
97% relevant
This article covers the same underlying N-able N-central exploitation event and adds concrete defender details: both CVE-2026-18556 and CVE-2026-18577 are being exploited, N-able's hotfix version is 2026.3.1.7, and observed post-compromise activity includes Cloudflare tunnels, suspicious executables, and abuse of Take Control for persistence and remote access.
Bill Toulas
2026.08.03
98% relevant
This article is the same underlying event: N-able warning that CVE-2026-18577 in N-central is being actively exploited and urging customers to apply hotfix 2026.3.1.7. It adds details that the flaw affects hosted and on-premises deployments, is an incomplete fix for CVE-2026-18576, and includes vendor-supplied indicators of compromise such as specific IPs and abuse of Cloudflared.
Eduard Kovacs
2026.08.03
100% relevant
This article establishes a new tracked event: active exploitation of N-able N-central CVE-2026-18577, a patch-bypass authentication bypass affecting MSP remote-management infrastructure.