CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

August 4, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: Organizations using N-able N-central RMM
Incident: Active exploitation of an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central.
Impact: Full administrative account takeover and unauthorized lateral movement to all managed endpoints.
Attacker: Unidentified threat actors
Analysis: The vulnerability CVE-2026-18577 allows attackers to bypass authentication and take over accounts, providing a direct foothold in the RMM server. From there, adversaries use the built-in ‘Take Control’ feature to move laterally into managed endpoints and deploy persistence. The use of VPN exit nodes and the Cloudflared utility helps mask malicious outbound traffic as legitimate.
Recommendations: Update N-central to version 2026.3 HF1 immediately; Audit ‘Take Control’ session logs for unauthorized or anomalous activity; Monitor for ‘svchost.exe’ in user documents and unauthorized ‘Cloudflared’ services
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *