Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short
ID: 61b9ff2b-9bfb-55bb-bfb3-4ba029163253
STIX ID: report--61b9ff2b-9bfb-55bb-bfb3-4ba029163253
Feed Name: HackRead
Threat Score
N-able issued an emergency hotfix for N-central after attackers exploited an authentication bypass (CVE-2026-18577, CVSS 8.2) to obtain remote admin access, pivot to managed endpoints via the Take Control feature, and install Cloudflare tunnels (persisted as a service named "Cloudflared") to maintain access; administrators must install hotfix 2026.3.1.7 and inspect endpoints for indicators such as a svchost.exe in user Documents and the Cloudflared service.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
