N-able security patch release for CVE-2026-18577
Security Patch Release
Summary
Hide ▲
Show ▼
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3.1.7 for all versions before 2026.3, after earlier investigation found remote administrative access on servers running 2026.1 and earlier. N-able says hosted deployments already received the update, while on-premises customers must install it manually. The company also provided IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.
Related Happenings
N-able security patch release for CVE-2026-18576
Security Patch Release
H score48
First: 05.08.2026 18:51
Last: 05.08.2026 18:51
Sources 1
About this happening:
N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urge...
N-able security patch release for CVE-2026-18576
Security Patch ReleaseAbout this happening: N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urge...
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentHow related: N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector Action
H score37
First: 23.07.2026 11:13
Last: 23.07.2026 11:13
Sources 1
About this happening:
CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
CISA BOD 26-04 patch directive for CVE-2026-16232
Public Sector ActionAbout this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...
ServiceNow security patch release for CVE-2026-6875
Security Patch Release
H score47
First: 20.07.2026 12:29
Last: 20.07.2026 12:29
Sources 1
About this happening:
ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
ServiceNow security patch release for CVE-2026-6875
Security Patch ReleaseAbout this happening: ServiceNow released CVE-2026-6875 security updates for the ServiceNow AI Platform, covering hosted and self-hosted instances. The patch addresses a pre-auth sand...
Timeline
-
03.08.2026 09:41 1 articles · 4d ago
N-able begins investigating unusual N-central licensing errors
Detection Ioc UpdateN-able began investigating after an unusual volume of licensing errors from on-premises N-central customers, and the investigation found that an attacker had remotely gained administrative access to servers running 2026.1 and earlier.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
-
03.08.2026 09:41 3 articles · 4d ago
N-able ships 2026.3.1.7 as the first unaffected N-central build
Mitigation Patch UpdateN-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version, told customers that upgrading to 2026.3 was no longer sufficient, and required every N-central customer to move to 2026.3.1.7.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able warns of N-central auth bypass flaw exploited in attacks — www.bleepingcomputer.com — 03.08.2026 20:00