N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an incomplete fix for CVE-2026-18556, and the company shipped 2026.3.1.7 as the first unaffected release after finding a bypass of the earlier patch. The vendor said it detected active exploitation on August 1 and published IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder. CISA added CVE-2026-18577 to KEV on August 5, 2026 and told FCEB agencies to apply fixes by August 6 and review Take Control activity.
Related Happenings
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577.
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentHow related: As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577.
About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
H score47
First: 31.07.2026 18:00
Last: 31.07.2026 18:00
Sources 1
How related:
The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.
About this happening:
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
CampaignHow related: The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.
About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation Wave
H score18
First: 01.06.2026 11:30
Last: 01.06.2026 11:30
Sources 1
About this happening:
CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation WaveAbout this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
Federal civilian executive branch agency hit by network compromise
Incident
H score21
First: 24.04.2026 23:34
Last: 24.04.2026 23:34
Sources 1
About this happening:
A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Federal civilian executive branch agency hit by network compromise
IncidentAbout this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware Activity
H score33
First: 23.04.2026 15:00
Last: 23.04.2026 15:00
Sources 1
About this happening:
CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
FIRESTARTER malware on Cisco ASA and FTD devices
Malware ActivityAbout this happening: CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...
Latest development: 24.04.2026 23:34
CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.
Timeline
-
04.08.2026 10:00 2 articles · 3d ago
CISA adds CVE-2026-18577 to KEV after active exploitation
Legal Policy Action UpdateCISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.
Show sources
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises — thehackernews.com — 04.08.2026 10:00
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited — thehackernews.com — 05.08.2026 10:40
-
03.08.2026 09:41 1 articles · 4d ago
N-able investigates licensing errors and finds remote administrative access on N-central servers
Detection Ioc UpdateN-able began investigating unusual licensing errors from on-premises N-central customers on July 31 and determined that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, exposing customer systems managed through those servers.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
-
03.08.2026 09:41 3 articles · 4d ago
N-able ships N-central 2026.3.1.7 after the first fix proves incomplete
Mitigation Patch UpdateN-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version after finding an alternative way to exploit the same vulnerability that the earlier 2026.2 fix did not block. It said every customer should move to 2026.3.1.7 because upgrading to 2026.3 was no longer sufficient and versions before the emergency hotfix remained vulnerable.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able warns of N-central auth bypass flaw exploited in attacks — www.bleepingcomputer.com — 03.08.2026 20:00
- CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities — www.securityweek.com — 05.08.2026 12:44
-
03.08.2026 03:00 2 articles · 4d ago
Huntress links N-central exploitation to one partner account and nine organisations
Campaign Scope UpdateHuntress reported on August 3 that it had seen exploitation in one organisation in its customer base, later clarifying that the activity involved a self-hosted N-central instance within one partner account that reached nine organisations and one endpoint in each. Based on the evidence available, the post-compromise activity was limited to enumerating running processes before the attackers disconnected, and Huntress did not observe the Cloudflare installation activity described by N-able.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41