Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Spain’s politicians point finger at Morocco over Ceuta crisis – POLITICO

    August 3, 2026

    How Democratic Socialists Are Wrestling With Their Next Moves

    August 3, 2026

    Documents Undercut Trump’s Claims About Bears Ears National Monument

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Spain’s politicians point finger at Morocco over Ceuta crisis – POLITICO
    • How Democratic Socialists Are Wrestling With Their Next Moves
    • Documents Undercut Trump’s Claims About Bears Ears National Monument
    • Europe’s AI labeling and transparency rules are now in effect
    • Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm
    • Bernstein warns Clarity Act failure could spark another crypto selloff
    • Ike Theriot Helps Prepare Astronauts to Work on the Moon 
    • Deep-sea snails and mussels in Indian and Pacific Oceans contain microplastics, study finds
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    N-able warns of N-central auth bypass flaw exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.

    The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3.

    On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform.

    image

    In an update the next day, the company announced the hotfix and strongly recommended all customers to upgrade immediately to the new release.

    Hosted deployments already received the update, while customers of on-premises instances need to install it manually.

    N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and corporate IT departments to manage large clusters of multi-OS systems and network devices.

    Because of this, compromising these servers allows threat actors to extend the attack beyond N-able’s direct customers.

    The product was also targeted last year, in zero-day attacks that prompted CISA to issue an urgent alert.

    In the past, threat actors compromised other notable RMM/MSP platforms, including Kaseya VSA, ConnectWise ScreenConnect, SimpleHelp, and SolarWinds Orion.

    CVE-2026-18577 is the result of an incomplete patch for CVE-2026-18576, a vulnerability described as an “authentication bypass using an alternate path or channel, which affected all N-central versions through 2026.1. Both vulnerabilities could be exploited for administrative account takeover.

    N-able has not shared any technical details about the security issue or provided information about the number of customers targeted or compromised through CVE-2026-18577.

    The vendor provided indicators of compromise on the hotfix download page, including four specific IP addresses, a registered service named ‘Cloudflared,’ and ‘svchost.exe’ in the users’ documents folder.

    If any of these are found, customers are advised to contact N-able support immediately and engage their own security team.

    It should be noted that attackers frequently abuse Cloudflared, the legitimate tunneling utility from Cloudflare, to create outbound tunnels that expose compromised machines or provide remote access without opening inbound firewall ports.

    The vendor also says that agents do not need immediate updates to mitigate CVE-2026-18577, but the action is recommended to get the latest fixes and features.

    N-able’s status update “strongly recommends” that customers remain vigilant and monitor their environments closely, while the company also promised to share more updates as quickly as possible.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks auth Bypass Exploited Flaw Nable Ncentral warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Chinese Actor Weaponizes Deepseek AI Agent Against Security Firm

    Bernstein warns Clarity Act failure could spark another crypto selloff

    AI is both a cyber weapon and a massive target, CrowdStrike warns

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

    ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

    Is There Really a Fix for CISO Fatigue?

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Spain’s politicians point finger at Morocco over Ceuta crisis – POLITICO

    August 3, 2026

    How Democratic Socialists Are Wrestling With Their Next Moves

    August 3, 2026

    Documents Undercut Trump’s Claims About Bears Ears National Monument

    August 3, 2026

    Europe’s AI labeling and transparency rules are now in effect

    August 3, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Spain’s politicians point finger at Morocco over Ceuta crisis – POLITICO

    August 3, 2026

    How Democratic Socialists Are Wrestling With Their Next Moves

    August 3, 2026

    Documents Undercut Trump’s Claims About Bears Ears National Monument

    August 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.