Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities The Hacker News

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

CISA has added CVE-2026-18577 (CVSS 8.2), an authentication bypass flaw in N-able N-central, to its KEV catalog due to active exploitation allowing account takeover and administrative access. The vulnerability is a case of incomplete patching for CVE-2026-18556 and has been addressed in N-central version 2026.3 HF1. Successful exploitation enables attackers to pivot to managed endpoints using the Take Control feature, with observed IOCs including specific VPN exit node IP addresses and a malicious "svchost.exe" file.
Read Full Article →

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises  Ravie Lakshmanan  Aug 04, 2026 Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities ( KEV ) catalog following reports of active exploitation in the wild. The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows authentication bypass and account takeover in susceptible versions of the software. The issue has been addressed in version 2026.3 HF1. "N-able N-central contains an authentication bypass using an alternate path or channel [that] allows for authentication bypass and account takeover in N-central," CISA said. Successful exploitation of the vulnerability can permit remote attackers to gain administrative access to vulnerable N-central servers and then abuse the built-in Take Control feature to pivot into managed endpoints and deploy persistence mechanisms. N-able has shared the following indicators of compromise - Review device users' documents folder for a file called "svchost.exe," as well as look for a registered service name called "Cloudflared," a legitimate tunneling utility from Cloudflare that's frequently abused by bad actors to set up covert, outbound connections and disguise malicious operations as legitimate traffic. Scan for inbound connections from any of the below IP addresses - 173.249.252[.]200 87.249.138[.]34 37.19.210[.]32 68.235.46[.]214 The malicious activity has not been publicly attributed to any known threat actor or group. However, Huntress said it observed threat actors targeting the flaw across multiple organizations. There is no indication that it has turned into a broad, indiscriminate campaign at this stage. Some of the patterns observed post successful exploitation include - Conducting high-level reconnaissance to target key servers, such as domain controllers Enumerating running processes on a compromised host before disconnecting Moving laterally to other hosts in impacted organizations' environments after gaining initial access In at least one case, the threat actor has been found making a malicious connection via "MSP Support," a default username tied to legitimate N-Central Take Control sessions, from the IP address "173.249.252[.]200." All the aforementioned four IP addresses are Mullvad or NordVPN VPN exit nodes. "Notably, among the original IPs, we have seen substantial traffic with 87.249.138[.]34 directly attributed to NordVPN, as well as substantial traffic with 37.19.210[.]32 directly attributed to Mullvad VPN," Huntress said . "37.19.210[.]32 has been previously abused for bruteforcing, spam, and other nefarious activity prior to this incident." As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577. The development underscores continued exploitation of widely deployed remote monitoring and management (RMM) platforms to facilitate persistent access to target networks. In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are being recommended to apply the fixes by August 6, 2026, and review N-central Take Control activity in their environment. The exploitation of CVE-2026-18577 comes almost exactly one year after two other flaws in the product ( CVE-2025-8875 and CVE-2025-8876 ) were weaponized in limited attacks targeting on-premises environments. Found this article interesting? Follow us on Google News , Twitter and LinkedIn to read more exclusive content we post. SHARE      Tweet  Share  Share  Share   Share on Facebook  Share on Twitter  Share on Linkedin  Share on Reddit  Share on Hacker News  Share on Email  Share on WhatsApp Share on Facebook Messenger  Share on Telegram SHARE  Access Management , Cloud security , enterprise security , exploitation , Malware , network security , Vulnerability , Zero Trust ⚡ Top Stories This Week New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers Claude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac Files ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable ⭐ Featured Resources [Webinar] How Militaries Can Trust the Data Behind Autonomous Missions Download the 5-Step Action Plan for AI-Speed Exploitation Get the Checklist for Gaining Control of AI Use Across Your Organization Get the 2026 CISO Benchmark Report Based on 600 Security Leaders

Share this article