logo

CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints

ID: f0fffaf0-e8bc-523b-adf5-67cf161b1253

STIX ID: report--f0fffaf0-e8bc-523b-adf5-67cf161b1253

Feed Name: SOC Prime Blog

Threat Score
85/100

Date Published: 2026-08-04

Date Updated: 2026-08-06

Author: SOC Prime Team

...
...

N-able released an urgent hotfix (N-central 2026.3.1.7) for CVE-2026-18577, an authentication-bypass vulnerability in N-central that has been actively exploited to gain administrative control of RMM servers and pivot to managed endpoints. Threat actors used the platform's Take Control capability to deploy persistence (a svchost.exe in user Documents and a Windows service named 'Cloudflared' running a Cloudflare Tunnel) enabling outbound access that survives reboots. The vendor and CISA advise immediate patching, investigation of console and Take Control activity, endpoint searches for the published IOCs, and restricting management interface access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.