Skip to main content

We've updated our Privacy Policy. Questions? Email us any time at privacy@ground.news

Published loading...Updated

N-Able Warns of N-Central Auth Bypass Flaw Exploited in Attacks

The company said the flaw gave attackers unauthenticated administrative access and let them plant persistent Cloudflare tunnels on managed endpoints.

  • N-Able released an emergency patch, build 2026.3.1.7, on August 2 to address a critical authentication bypass vulnerability in N-central, fixing two administrative account takeover flaws, CVE-2026-18556 and CVE-2026-18577, that attackers actively exploited.
  • Administrative account takeover allows attackers to bypass credentials; because N-central is RMM software used by managed service providers to control thousands of customer machines from one console, compromising a single server grants access to every managed endpoint.
  • Huntress traced activity to one self-hosted N-central instance, where attackers registered Cloudflared as Windows services to bypass firewalls and survive reboots, reaching nine organisations and touching one endpoint in each.
  • Patching N-central does not automatically evict intruders because tunnels keep them connected; N-able advised customers to manually hunt for tunnel services, flagging suspicious files in user Documents folders and traffic to published IP addresses.
  • Researchers in Finland warned that every version before the hotfix was vulnerable, urging exposed customers to take N-central offline, as 55.6% of reachable servers remained unpatched at the time of Huntress's update.
Insights by Ground AI

17 Articles

Lean Right

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting N-able N-central to its list of known exploitable vulnerabilities. CISA added the vulnerability to its Known Vulnerabilities (KEV) list on Monday following reports of active exploitation in the wild. Details of the vulnerability: The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is an incomplete patch for CVE-2026-1855…

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 60% of the sources are Center
60% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

Cyber Security News broke the news on Monday, August 3, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal