Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
ID: 3f3e3617-741b-558e-a0e3-8b3c7473952a
STIX ID: report--3f3e3617-741b-558e-a0e3-8b3c7473952a
Feed Name: Help Net Security
Threat Score
Attackers are actively exploiting an authentication-bypass vulnerability (CVE-2026-18577) in N-able N-central to compromise admin accounts, use the Take Control feature to access managed endpoints, and establish persistence by registering a Cloudflared service; N-able released hotfix 2026.3.1.7 and advises self-hosted customers to patch, check for the 'svchost.exe' file and a 'Cloudflared' service on managed devices, and review logs and recent Take Control sessions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
