Ethical Hacking News
CISA has added a high-severity security flaw impacting N-able N-central to its KEV catalog following reports of active exploitation in the wild. Users are advised to apply available fixes by August 6, 2026, review Take Control feature activity, and stay up-to-date with the latest security patches to minimize potential damage from this vulnerability.
N-able N-central users must apply available fixes by August 6, 2026, to patch CVE-2026-18577.The vulnerability allows authentication bypass and account takeover in susceptible versions of the software.CISA has shared indicators of compromise (IOCs) to help identify malicious activity.Successful exploitation can permit remote attackers to gain administrative access to vulnerable servers.IT professionals should consider implementing additional security measures, such as monitoring for suspicious activity and configuring audit logs.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild. This recent development underscores the importance of keeping software up-to-date, particularly for remote monitoring and management (RMM) platforms such as N-able N-central.
The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows authentication bypass and account takeover in susceptible versions of the software. In other words, this vulnerability enables attackers to gain unauthorized access to N-central servers by exploiting an alternate path or channel, which ultimately leads to account takeover.
CISA has emphasized the need for N-able N-central users to take immediate action and apply the fixes by August 6, 2026, as well as review their Take Control feature activity in their environment. The agency has also shared some important indicators of compromise (IOCs) that can help identify malicious activity, including a file called "svchost.exe" in the device users' documents folder, a registered service name called "Cloudflared," and IP addresses such as 173.249.252[.]200, 87.249.138[.]34, 37.19.210[.]32, and 68.235.46[.]214.
In addition to the IOCs, successful exploitation of this vulnerability can permit remote attackers to gain administrative access to vulnerable N-central servers, allowing them to abuse the built-in Take Control feature to pivot into managed endpoints and deploy persistence mechanisms. The malicious activity has not been publicly attributed to any known threat actor or group, but Huntress said it observed threat actors targeting the flaw across multiple organizations.
The exploitation of CVE-2026-18577 comes almost exactly one year after two other flaws in N-central were weaponized in limited attacks targeting on-premises environments. This latest development highlights the ongoing importance of staying vigilant and proactive when it comes to addressing security vulnerabilities in widely deployed RMM platforms like N-able N-central.
To minimize potential damage from this vulnerability, users are advised to review their N-central Take Control activity, apply any available fixes by August 6, 2026, and stay up-to-date with the latest security patches. Furthermore, IT professionals should consider implementing additional security measures such as monitoring for suspicious activity, configuring audit logs, and conducting regular security assessments.
In conclusion, the recent addition of CVE-2026-18577 to CISA's KEV catalog serves as a timely reminder of the importance of keeping software up-to-date and addressing security vulnerabilities in a proactive manner. By staying vigilant and taking swift action, users can minimize potential damage from this vulnerability and protect their networks against malicious activity.
CISA has added a high-severity security flaw impacting N-able N-central to its KEV catalog following reports of active exploitation in the wild. Users are advised to apply available fixes by August 6, 2026, review Take Control feature activity, and stay up-to-date with the latest security patches to minimize potential damage from this vulnerability.
Related Information:
https://www.ethicalhackingnews.com/articles/CISA-Adds-Exploited-N-able-N-central-Flaw-to-KEV-After-Customer-Compromises-ehn.shtml
https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
https://blog.netmanageit.com/cisa-adds-exploited-n-able-n-central-flaw-to-kev-after-customer-compromises/
https://nvd.nist.gov/vuln/detail/CVE-2026-18577
https://www.cvedetails.com/cve/CVE-2026-18577/
https://nvd.nist.gov/vuln/detail/CVE-2026-18556
https://www.cvedetails.com/cve/CVE-2026-18556/
Published: Tue Aug 4 03:38:35 2026 by llama3.2 3B Q4_K_M