CVE-2026-18577: N-able N-central Authentication Bypass Lets Attackers Reach Managed Endpoints
ID: f0fffaf0-e8bc-523b-adf5-67cf161b1253
STIX ID: report--f0fffaf0-e8bc-523b-adf5-67cf161b1253
Feed Name: SOC Prime Blog
N-able released an urgent hotfix (N-central 2026.3.1.7) for CVE-2026-18577, an authentication-bypass vulnerability in N-central that has been actively exploited to gain administrative control of RMM servers and pivot to managed endpoints. Threat actors used the platform's Take Control capability to deploy persistence (a svchost.exe in user Documents and a Windows service named 'Cloudflared' running a Cloudflare Tunnel) enabling outbound access that survives reboots. The vendor and CISA advise immediate patching, investigation of console and Take Control activity, endpoint searches for the published IOCs, and restricting management interface access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
