logo

Hackers Exploit N-able N-central Flaw After Initial Fix Falls Short

ID: 61b9ff2b-9bfb-55bb-bfb3-4ba029163253

STIX ID: report--61b9ff2b-9bfb-55bb-bfb3-4ba029163253

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: Waqas

...
...

N-able issued an emergency hotfix for N-central after attackers exploited an authentication bypass (CVE-2026-18577, CVSS 8.2) to obtain remote admin access, pivot to managed endpoints via the Take Control feature, and install Cloudflare tunnels (persisted as a service named "Cloudflared") to maintain access; administrators must install hotfix 2026.3.1.7 and inspect endpoints for indicators such as a svchost.exe in user Documents and the Cloudflared service.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.