logo

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

ID: 053d026f-ffe4-52ad-9963-f31f00f74376

STIX ID: report--053d026f-ffe4-52ad-9963-f31f00f74376

Feed Name: Help Net Security

Threat Score
85/100

Date Published: 2026-08-10

Date Updated: 2026-08-10

Author: Zeljka Zorz

...
...

**Active exploitation of N‑able N‑central zero-day (CVE-2026-18577):** N‑able released Hotfix 2 after detecting a bypass variant being actively exploited to compromise N‑central instances, with attackers using Take Control to access endpoints, establish CloudFlare tunnel persistence, create domain accounts, disable EDR, perform rapid lateral movement and deploy ransomware linked to Storm-1175; N‑able and researchers published IOCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.