logo

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

ID: 5a7a042f-c43c-5931-b25f-c9dbf575a40f

STIX ID: report--5a7a042f-c43c-5931-b25f-c9dbf575a40f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-08-03

Date Updated: 2026-08-03

Author: [email protected] (The Hacker News)

ADMIRALTY:B6
...
...

An authentication-bypass in N-able N-central (CVE-2026-18556 and the subsequently related CVE-2026-18577) was exploited to gain administrative access to on-premises N-central servers and pivot to managed endpoints; attackers used Take Control and registered Cloudflare tunnels as services to maintain persistent, outbound-accessible remote access. N-able released hotfix build 2026.3.1.7, published six IP addresses observed in the attacks, and advised customers to upgrade and hunt for indicators (e.g., svchost.exe in Documents, a Cloudflared service, traffic from published IPs); Huntress and Finland's CERT provided complementary detection guidance and observed limited exploitation in their telemetry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.