Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Blanche’s Documents Addressing Trump I.R.S. Deal Leave Loopholes

    August 3, 2026

    AstraZeneca and Bristol-Myers: when Big Pharma isn’t big enough

    August 3, 2026

    AI is both a cyber weapon and a massive target, CrowdStrike warns

    August 3, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Blanche’s Documents Addressing Trump I.R.S. Deal Leave Loopholes
    • AstraZeneca and Bristol-Myers: when Big Pharma isn’t big enough
    • AI is both a cyber weapon and a massive target, CrowdStrike warns
    • Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)
    • Crypto Clarity Act Risks More Delay As Recess Looms
    • Ancient Arctic carbon is pouring into the sea, but the seabed captures most of it
    • Documentary captures impacts of diamond mining along South Africa’s West Coast
    • Italian startup testing offshore wind energy storage technology off Calabria
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 3
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    N-able warns of N-central auth bypass flaw exploited in attacks

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 3, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.

    The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3.

    On August 1st, the vendor disclosed that it detected active exploitation and launched an investigation that uncovered additional security concerns affecting all versions of N-central, its flagship Remote Monitoring and Management (RMM) platform.

    image

    In an update the next day, the company announced the hotfix and strongly recommended all customers to upgrade immediately to the new release.

    Hosted deployments already received the update, while customers of on-premises instances need to install it manually.

    N-central is a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and corporate IT departments to manage large clusters of multi-OS systems and network devices.

    Because of this, compromising these servers allows threat actors to extend the attack beyond N-able’s direct customers.

    The product was also targeted last year, in zero-day attacks that prompted CISA to issue an urgent alert.

    In the past, threat actors compromised other notable RMM/MSP platforms, including Kaseya VSA, ConnectWise ScreenConnect, SimpleHelp, and SolarWinds Orion.

    CVE-2026-18577 is the result of an incomplete patch for CVE-2026-18576, a vulnerability described as an “authentication bypass using an alternate path or channel, which affected all N-central versions through 2026.1. Both vulnerabilities could be exploited for administrative account takeover.

    N-able has not shared any technical details about the security issue or provided information about the number of customers targeted or compromised through CVE-2026-18577.

    The vendor provided indicators of compromise on the hotfix download page, including four specific IP addresses, a registered service named ‘Cloudflared,’ and ‘svchost.exe’ in the users’ documents folder.

    If any of these are found, customers are advised to contact N-able support immediately and engage their own security team.

    It should be noted that attackers frequently abuse Cloudflared, the legitimate tunneling utility from Cloudflare, to create outbound tunnels that expose compromised machines or provide remote access without opening inbound firewall ports.

    The vendor also says that agents do not need immediate updates to mitigate CVE-2026-18577, but the action is recommended to get the latest fixes and features.

    N-able’s status update “strongly recommends” that customers remain vigilant and monitor their environments closely, while the company also promised to share more updates as quickly as possible.


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper

    attacks auth Bypass Exploited Flaw Nable Ncentral warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    AI is both a cyber weapon and a massive target, CrowdStrike warns

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

    ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks

    Is There Really a Fix for CISO Fatigue?

    AI is making cybersecurity fundamentals more important than ever

    River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Blanche’s Documents Addressing Trump I.R.S. Deal Leave Loopholes

    August 3, 2026

    AstraZeneca and Bristol-Myers: when Big Pharma isn’t big enough

    August 3, 2026

    AI is both a cyber weapon and a massive target, CrowdStrike warns

    August 3, 2026

    Black Hat USA 2026 – Summary of Vendor Announcements (Part 1)

    August 3, 2026
    Latest Posts

    A Russian Spy, Suddenly Cast Into the Spotlight, Flees Japan

    July 23, 2026

    Did Trump accidentally declassify proof Russia tried to help him win 2020 election?

    July 23, 2026

    Trump Puts Section 338 Tariffs on Canada as Greer Foreshadows New Global Duties

    July 23, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Blanche’s Documents Addressing Trump I.R.S. Deal Leave Loopholes

    August 3, 2026

    AstraZeneca and Bristol-Myers: when Big Pharma isn’t big enough

    August 3, 2026

    AI is both a cyber weapon and a massive target, CrowdStrike warns

    August 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.