Ethical Hacking News
U.S. CISA has added a critical N-able N-central flaw to its Known Exploited Vulnerabilities catalog, allowing remote attackers to gain administrative access to vulnerable systems. This vulnerability highlights the importance of prioritizing patching and securing RMM platforms.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a N-able N-central vulnerability to its Known Exploited Vulnerabilities catalog with a CVSS score of 8.2. Remote attackers can take over accounts and gain administrative access to vulnerable N-able N-central servers using this exploit. Attackers have used the Take Control feature to move into managed endpoints, establish persistent access, and conduct reconnaissance across networks. A limited number of customers were compromised, but more than half of reachable N-central cloud servers remained unpatched against CVE-2026-18577. CISA urges federal agencies to fix the vulnerability by August 6, 2026, and private organizations to review their KEV catalog and address vulnerabilities in their infrastructure.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has recently added a N-able N-central flaw, tracked as CVE-2026-18577, to its Known Exploited Vulnerabilities (KEV) catalog. The CVSS score of this vulnerability is 8.2, making it a high-severity exploit that can be used by remote attackers to take over accounts and gain administrative access to vulnerable N-able N-central servers. This vulnerability was caused by an incomplete fix for a previous vulnerability tracked as CVE-2026-18556.
Once inside the system, attackers can use the built-in Take Control feature to move into managed endpoints and establish persistent access. Huntress researchers observed that attackers exploiting this vulnerability have been conducting reconnaissance, targeted domain controllers, enumerated processes, and moved laterally across networks.
It is worth noting that a limited number of customers were compromised in this incident. N-able confirmed that they had engaged directly with impacted customers to provide support and upgrades to the latest version of N-central. However, more than half (55.6%) of reachable N-central cloud servers used by partners and customers remained unpatched against CVE-2026-18577, leaving them exposed to exploitation.
CISA urges federal agencies to fix this vulnerability by August 6, 2026. Experts also recommend that private organizations review the KEV catalog and address the vulnerabilities in their infrastructure. In addition, organizations can check for compromise by looking for a suspicious svchost.exe file in users' Documents folders or registered Cloudflared services, and inbound firewall connections from specific IP addresses.
In light of this new vulnerability, it is essential to prioritize patching remote monitoring and management (RMM) platforms to prevent similar incidents. Furthermore, organizations must be proactive in identifying vulnerabilities and taking steps to protect their networks against attacks exploiting known exploited vulnerabilities.
Related Information:
https://www.ethicalhackingnews.com/articles/US-CISA-Adds-N-able-N-Central-Flaw-to-Known-Exploited-Vulnerabilities-Catalog-A-Growing-Concern-for-Remote-Monitoring-and-Management-ehn.shtml
https://securityaffairs.com/196585/security/u-s-cisa-adds-a-n-able-n-central-flaw-to-its-known-exploited-vulnerabilities-catalog.html
https://nvd.nist.gov/vuln/detail/CVE-2026-18577
https://www.cvedetails.com/cve/CVE-2026-18577/
https://nvd.nist.gov/vuln/detail/CVE-2026-18556
https://www.cvedetails.com/cve/CVE-2026-18556/
Published: Tue Aug 4 07:37:07 2026 by llama3.2 3B Q4_K_M