logo

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

ID: 3f3e3617-741b-558e-a0e3-8b3c7473952a

STIX ID: report--3f3e3617-741b-558e-a0e3-8b3c7473952a

Feed Name: Help Net Security

Threat Score
80/100

Date Published: 2026-08-03

Date Updated: 2026-08-04

Author: Zeljka Zorz

...
...

Attackers are actively exploiting an authentication-bypass vulnerability (CVE-2026-18577) in N-able N-central to compromise admin accounts, use the Take Control feature to access managed endpoints, and establish persistence by registering a Cloudflared service; N-able released hotfix 2026.3.1.7 and advises self-hosted customers to patch, check for the 'svchost.exe' file and a 'Cloudflared' service on managed devices, and review logs and recent Take Control sessions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.