Security News

Cybersecurity news aggregator

CRITICAL Attacks Dark Reading

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

Attackers are exploiting CVE-2026-18577 (CVSS 8.2), a patch bypass for a prior authentication bypass flaw (CVE-2026-18556) in N-able N-central, to gain administrative access to RMM servers. Following exploitation, threat actors use the platform's "Take Control" feature to access managed endpoints and deploy persistent Cloudflare tunnels. N-able has released a fix in N-central version 2026.3.1.7, which hosted customers receive automatically and on-premises customers must apply manually.
Read Full Article →

Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources VULNERABILITIES & THREATS REMOTE WORKFORCE IDENTITY & ACCESS MANAGEMENT SECURITY APPLICATION SECURITY NEWS Attackers Exploit N-able Patch Bypass Flaw on RMM Servers Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access. Alexander Culafi,Senior News Writer,Dark Reading August 3, 2026 3 Min Read SOURCE: JHVEPHOTO VIA GETTY IMAGES N-able recently disclosed that a threat actor targeted its N-central product through a patch bypass vulnerability and used the flaw to gain access to customer environments. The company, which sells security and IT management tools to managed service providers (MSPs) and internal IT teams, disclosed active exploitation over the weekend through its status update page and on an Aug. 2 blog post. N-central is N-able's remote monitoring and management (RMM) platform, used to remotely monitor customer systems and do things like deploy software, scripts, and patches as needed. RMM can also be used to remotely access customer endpoints through the "Take Control" feature. LOADING... According to the blog post, N-able on July 31 saw "an increase in licensing issues for our on-premises N‑central customers." Its security teams were engaged to investigate, and on the morning of Aug. 2, personnel found that a previously addressed vulnerability, authentication bypass CVE-2026-18556, contained another vector a threat actor could, and did, exploit to obtain administrative access to vulnerable N-central servers. Related:'Certighost' Flaw Haunts Microsoft Active Directory Certificates "Following exploitation, the attacker leveraged the Take Control feature and connected to systems within the N‑central managed environment," the disclosure blog post read. "Once on those devices, the attackers registered a new service for a CloudFlare tunnel, enabling persistence into an environment after access to the N‑central server was revoked." N-able's engineering team developed and published a fix to this vulnerability, tracked as CVE-2026-18577 (CVSS score 8.2). The company has identified that a "limited number of customers" have been impacted by the vulnerability to date, and N-able says its support team has engaged these customers directly. Upgrade and Lock Down Your N-central Instances LOADING... N-able recommends customers not running the most recent version of N-central to upgrade to version 2026.3.1.7. Hosted customers receive the fix automatically, while on-premises customers must apply the fix themselves. Huntress said in a blog post on Aug. 3 that CVE-2026-18577 remains under active exploitation, and it has seen exploitation impacting one organization in its customer base so far. Moreover, Huntress has seen "many environments" where an N-central Server had not yet been updated to 2026.3.1.7. Nearly all cloud-hosted servers have been patched as of now. 13.6% of reachable servers remain unpatched, with the majority being self-hosted; 28.6% of reachable N-central self-hosted servers remain unpatched. Related:Vatican's Official Prayer App Leaks 700K+ Global Users' PII John Hammond, senior principal security researcher at Huntress, tells Dark Reading that while telemetry shows confirmed post-exploitation activity in more than one partner environment, there are not yet signs that this has become a broad, indiscriminate campaign across its MSP base. "In the intrusions we've analyzed, the actor uses N-central access to pivot into high-value servers, usually domain controllers, and immediately pulls a process list to understand what’s running and decide on next steps," he explains. "Because a compromised N-central server can push code and tools to many connected endpoints, the potential blast radius is large, so we're treating all vulnerable deployments as high risk even though confirmed exploitation is still limited to a small set of customers." The stakes for compromise are high, the researchers noted in the blog; a compromised server can be used to "run scripts, push tools, and open remote sessions across every downstream endpoint it manages." The blog post compared it to a kind of "god-mode" you would find in a video game. Both N-able's disclosure and Huntress' blog post includes indicators of compromise. In addition to patching, Huntress also recommends orgs harden their N-central environment; scan logins, accounts and configurations for "changes and events that do not match your normal operational patterns"; review remote control activity; and assess whether temporarily disabling N-central is appropriate. Related:25 Years After Code Red: What the Worm Era Can Teach Us About AI Security N-able has not responded to Dark Reading's request for comment at press time. About the Author Alexander Culafi Senior News Writer, Dark Reading Alex is an award-winning writer, journalist, and podcast host based in Boston. After cutting his teeth writing for independent gaming publications as a teenager, he graduated from Emerson College in 2016 with a Bachelor of Science in journalism. He has previously been published on VentureFizz, Search Security, Nintendo World Report, and elsewhere. At Dark Reading, he covers a variety of cybersecurity topics, including the cybercrime ecosystem, open source security, and the intersection between AI and threat actors. In his spare time, Alex hosts the weekly Nintendo podcast, "Talk Nintendo Podcast," and works on personal writing projects, including two previously self-published science fiction novels. He has received numerous awards, including TechTarget's Writer of the Year in 2022 as well as more than 10 Azbee awards for his reporting between 2022 and today. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections 0-Day to 10x Discovery: Security at the Speed of Mythos When AI Becomes an Insider: Rethinking Risk in Critical Infrastructure Governing the Agent; Identity Security in the Age of Autonomous AI More Webinars You May Also Like VULNERABILITIES & THREATS Exchange Flaw Lets Attackers Spoof Any Email Address by Alexander Culafi JUN 09, 2026 VULNERABILITIES & THREATS Cheap Hardware Module Bypasses AMD, Intel Memory Encryption by Rob Wright NOV 25, 2025 VULNERABILITIES & THREATS Patch Now: Microsoft Flags Zero-Day & Critical Zero-Click Bugs by Jai Vijayan NOV 11, 2025 VULNERABILITIES & THREATS Microsoft Issues Emergency Patch for Critical Windows Server Bug by Rob Wright OCT 24, 2025 Black Hat USA Coverage APPLICATION SECURITY AI Harnesses Burst With Potential Exploit Opps byRobert Lemos JUL 30, 2026 4 MIN READ APPLICATION SECURITY When AppSec Scanners Become a Supply Chain Attack Vector byEricka Chickowski JUL 29, 2026 5 MIN READ CYBERSECURITY OPERATIONS Red Agents vs. Blue Agents: How to Make AI Better at Defense byRob Wright JUL 29, 2026 5 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE LOADING... AUG 1-6 | MANDALAY BAY, LAS VEGAS USE CODE: DARKREADING & SAVE $200 ON A BRIEFINGS PASS OR $100 ON A BUSINESS PASS The premier cybersecurity event returns. GET YOUR PASS Discover More Black Hat Omdia Working With Us About Us Meet the Editors Advertise Reprints Join Us NEWSLETTER SIGN-UP Follow Us Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466. Home| Cookie Policy| Privacy| Terms of Use Your Privacy Choices

Share this article