Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

N-able addresses critical N-central vulnerabilities exploited by attackers

  • What: Attackers exploit critical N-able N-central vulnerabilities
  • Impact: Attackers gain administrative access and establish persistence on customer systems
Read Full Article →

Vulnerability Management N-able addresses critical N-central vulnerabilities exploited by attackers August 3, 2026 Share By SC Staff As reported by The Hacker News, N-able is addressing critical vulnerabilities in its N-central remote monitoring and management platform that attackers have exploited to gain administrative access and compromise customer systems. Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrative access to N-central servers. The initial fix for CVE-2026-18556 was incomplete, leading to the discovery of CVE-2026-18577, which affected builds prior to version 2026.3.1.7. Once inside the N-central server, attackers utilized the Take Control feature to access managed endpoints. They then established persistence by registering Cloudflare tunnels as services on these devices, allowing them to maintain access even after the initial N-central connection was revoked. N-able has released a hotfix, build 2026.3.1.7, and urges all customers to upgrade immediately. Self-hosted servers require manual upgrades, while hosted instances will be updated automatically. Customers who suspect compromise must also manually remove malicious tunnel services from endpoints, as the N-central upgrade alone does not remove this persistence. N-able has not disclosed the number of affected customers or whether data was exfiltrated. Source: The Hacker News SC Staff Related Vulnerability Management Critical vulnerability in Rails Active Storage could lead to RCE SC Staff August 3, 2026 The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Vulnerability Management Coldcard hardware wallet firmware flaw led to $70 million Bitcoin theft SC Staff August 3, 2026 The vulnerability, identified by Block and detailed by Galaxy Research, occurred because a deterministic software pseudorandom number generator (PRNG) was used instead of the intended hardware random number generator (RNG) for seed generation. Vulnerability Management Adobe fixes critical vulnerabilities in Campaign Classic and Bridge SC Staff August 3, 2026 The critical vulnerability in Adobe Campaign Classic, identified as CVE-2026-48449, stems from incorrect authorization and poses a significant risk for remote code execution. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds

Share this article