logo

Critical N-able N-central Flaws Actively Exploited to Gain God-Mode Access to MSP Networks

ID: 8ab03176-e512-522c-a1d2-a650db833585

STIX ID: report--8ab03176-e512-522c-a1d2-a650db833585

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Tamilselvan

...
...

N-able N-central has critical vulnerabilities (CVE-2026-18556 and a bypass CVE-2026-18577) that are being actively exploited to achieve unauthenticated administrative access to MSP consoles; N-able released hotfix 2026.3.1.7 and is urging immediate patching while Huntress has observed active abuse and published IOCs. The compromise enables attackers to push scripts, deploy tools, and open remote-control sessions across all managed endpoints, and many cloud-hosted servers remain unpatched; recommended mitigations include removing public access, enforcing MFA, limiting IP ranges, auditing accounts and sessions, or taking affected consoles offline until remediated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.