N-able N-central servers hit by network compromise
Incident
Summary
Hide ▲
Show ▼
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take Control and Cloudflared services. N-able said the activity affected a limited number of customers, began with signs of abuse on August 1, and led to CVE-2026-18577 and the emergency release of hotfix 2026.3.1.7 as the first unaffected version. CISA later added CVE-2026-18577 to KEV after reports of active exploitation, and published indicators include four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.
Related Happenings
HashiCorp security patch release for CVE-2026-16498
Security Patch Release
H score37
First: 05.08.2026 17:27
Last: 05.08.2026 17:27
Sources 1
About this happening:
HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect s...
HashiCorp security patch release for CVE-2026-16498
Security Patch ReleaseAbout this happening: HashiCorp released Terraform MCP Server 1.1.0 to fix three Streamable HTTP flaws, including CVE-2026-16498 token reuse and CVE-2026-14869 SSRF, that could affect s...
N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
H score49
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
About this happening:
CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an i...
N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
VulnerabilityHow related: N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers.
About this happening: CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an i...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.
N-able security patch release for CVE-2026-18577
Security Patch Release
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3.
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseHow related: The company on Sunday released hotfix 2026.3.1.7 to address the security issue, which affects all versions of N-central before 2026.3.
About this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
H score47
First: 31.07.2026 18:00
Last: 31.07.2026 18:00
Sources 1
About this happening:
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
CampaignAbout this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
CISA orders federal mitigation of CVE-2026-16812
Public Sector Action
H score36
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
CISA orders federal mitigation of CVE-2026-16812
Public Sector ActionAbout this happening: CISA added CVE-2026-16812 to its Known Exploited Vulnerabilities catalog and ordered U.S. federal civilian executive branch agencies to mitigate it by July 30, 2...
Timeline
-
04.08.2026 10:00 2 articles · 3d ago
CISA adds N-able N-central flaw to KEV after active exploitation
Legal Policy Action UpdateCISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Show sources
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises — thehackernews.com — 04.08.2026 10:00
- CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities — www.securityweek.com — 05.08.2026 12:44
-
03.08.2026 09:41 1 articles · 4d ago
N-able begins investigating unusual licensing errors on N-central servers
Initial DisclosureN-able began investigating after an unusual volume of licensing errors from on-premises customers and found that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, giving access to customer systems managed through those servers.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
-
03.08.2026 09:41 2 articles · 4d ago
N-able ships build 2026.3.1.7 after finding an alternate N-central bypass
Mitigation Patch UpdateN-able said its earlier fix was incomplete, identified CVE-2026-18577, and shipped build 2026.3.1.7 as the first unaffected version. The company said N-central builds prior to 2026.3.1.7 were vulnerable, and Finland's national cyber security centre said an August 2 advisory found all versions available before the emergency hotfix were vulnerable.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able warns of N-central auth bypass flaw exploited in attacks — www.bleepingcomputer.com — 03.08.2026 20:00
-
03.08.2026 09:41 2 articles · 4d ago
Huntress reports limited post-compromise activity and publishes N-central attacker domains
Technical Analysis UpdateN-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and used Take Control and Cloudflare tunnels to persist on managed endpoints. Huntress said a rapid response published August 3 initially saw exploitation at one organisation in its customer base, published three attacker domains, and found the post-compromise activity it had seen was limited to enumerating running processes before the attackers disconnected.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41