Active Exploitation of N-able N-central Authentication Bypass Vulnerability
ID: 82cb73bf-3c52-5561-bead-b69d65fe71fe
STIX ID: report--82cb73bf-3c52-5561-bead-b69d65fe71fe
Feed Name: ThreatCluster
Threat Score
N-able released an emergency hotfix for CVE-2026-18577, an authentication bypass in N-central that allowed unauthenticated remote administrative access and was exploited in the wild before a patch. Attackers used the product's Take Control capability and deployed Cloudflare Tunnel services for persistent access; CISA listed the flaw in its KEV catalog, and the issue threatens managed service providers and enterprise IT teams running affected versions prior to 2026.3.1.7.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
