Close Menu
NCIJ Network NCIJ Network
    What's Hot

    OpenAI hits back at Apple over ‘oddly personal’ trade secrets fight

    August 4, 2026

    Purple Carrot Meal Kit Review: Tastier Than Meal Kits With Meat

    August 4, 2026

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    August 4, 2026
    Facebook X (Twitter) Instagram
    Trending
    • OpenAI hits back at Apple over ‘oddly personal’ trade secrets fight
    • Purple Carrot Meal Kit Review: Tastier Than Meal Kits With Meat
    • Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering
    • Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M
    • A shy bird found only in Nepal is waiting for the world to notice
    • SOCAR tightens its grip on Caspian Sea oil & gas project with Itochu stake buyout
    • Grain bin accidents remain deadly. One farmer hopes his family’s story can help.
    • After five brutal years of Taliban rule, Afghan women and girls need our help – and I have a plan | Gordon Brown
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 4
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 4, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananAug 04, 2026Vulnerability / Enterprise Security

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.

    The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows authentication bypass and account takeover in susceptible versions of the software. The issue has been addressed in version 2026.3 HF1.

    “N-able N-central contains an authentication bypass using an alternate path or channel [that] allows for authentication bypass and account takeover in N-central,” CISA said.

    Successful exploitation of the vulnerability can permit remote attackers to gain administrative access to vulnerable N-central servers and then abuse the built-in Take Control feature to pivot into managed endpoints and deploy persistence mechanisms.

    Cybersecurity

    N-able has shared the following indicators of compromise –

    • Review device users’ documents folder for a file called “svchost.exe,” as well as look for a registered service name called “Cloudflared,” a legitimate tunneling utility from Cloudflare that’s frequently abused by bad actors to set up covert, outbound connections and disguise malicious operations as legitimate traffic.
    • Scan for inbound connections from any of the below IP addresses –

      • 173.249.252[.]200
      • 87.249.138[.]34
      • 37.19.210[.]32
      • 68.235.46[.]214

    The malicious activity has not been publicly attributed to any known threat actor or group. However, Huntress said it observed threat actors targeting the flaw across multiple organizations. There is no indication that it has turned into a broad, indiscriminate campaign at this stage.

    Some of the patterns observed post successful exploitation include –

    • Conducting high-level reconnaissance to target key servers, such as domain controllers
    • Enumerating running processes on a compromised host before disconnecting
    • Moving laterally to other hosts in impacted organizations’ environments after gaining initial access

    In at least one case, the threat actor has been found making a malicious connection via “MSP Support,” a default username tied to legitimate N-Central Take Control sessions, from the IP address “173.249.252[.]200.” All the aforementioned four IP addresses are Mullvad or NordVPN VPN exit nodes.

    Cybersecurity

    “Notably, among the original IPs, we have seen substantial traffic with 87.249.138[.]34 directly attributed to NordVPN, as well as substantial traffic with 37.19.210[.]32 directly attributed to Mullvad VPN,” Huntress said. “37.19.210[.]32 has been previously abused for bruteforcing, spam, and other nefarious activity prior to this incident.”

    As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a “limited number of customers” were compromised through CVE-2026-18577. The development underscores continued exploitation of widely deployed remote monitoring and management (RMM) platforms to facilitate persistent access to target networks.

    In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are being recommended to apply the fixes by August 6, 2026, and review N-central Take Control activity in their environment.

    The exploitation of CVE-2026-18577 comes almost exactly one year after two other flaws in the product (CVE-2025-8875 and CVE-2025-8876) were weaponized in limited attacks targeting on-premises environments.

    adds CISA Compromises customer Exploited Flaw KEV Nable Ncentral
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    Secure AI adoption starts with API best practices

    Bitcoin self-custody: Coldcard flaw exposes a hidden risk

    150,000 Impacted by Madera Community Hospital Data Breach

    ExfilSquad hackers leak info of over 100,000 UK police officers, staff

    Anthropic: Security Gaps, Not Model Issues Led to Claude Attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    OpenAI hits back at Apple over ‘oddly personal’ trade secrets fight

    August 4, 2026

    Purple Carrot Meal Kit Review: Tastier Than Meal Kits With Meat

    August 4, 2026

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    August 4, 2026

    Hardware Wallet Firms Warn of Phishing Surge as Coldcard Losses Near $130M

    August 4, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    OpenAI hits back at Apple over ‘oddly personal’ trade secrets fight

    August 4, 2026

    Purple Carrot Meal Kit Review: Tastier Than Meal Kits With Meat

    August 4, 2026

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    August 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.