U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog
ID: 2ac31a53-4064-5bbc-b7e5-a83adfdd1396
STIX ID: report--2ac31a53-4064-5bbc-b7e5-a83adfdd1396
Feed Name: Security Affairs
CISA added CVE-2026-18577—an authentication bypass in N‑able N-central with CVSS 8.2—to its Known Exploited Vulnerabilities catalog after active exploitation was observed; attackers gained administrative access, used the Take Control feature to reach managed endpoints, performed reconnaissance and lateral movement, and a limited number of customers were confirmed compromised. The report lists IOCs (suspicious svchost.exe in user Documents, a registered Cloudflared service, several malicious IPs), notes many N-central cloud servers remain unpatched (55.6%), and urges immediate upgrades to N-central 2026.3.1.7 and contacting N‑able support if indicators are found.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
