Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 49
3 unique sources, 5 articles

Summary

Hide ▲

CVE-2026-18577 is an authentication bypass in N-able N-central that affects hosted and on-premises servers before 2026.3. N-able said the issue stems from an incomplete fix for CVE-2026-18556, and the company shipped 2026.3.1.7 as the first unaffected release after finding a bypass of the earlier patch. The vendor said it detected active exploitation on August 1 and published IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder. CISA added CVE-2026-18577 to KEV on August 5, 2026 and told FCEB agencies to apply fixes by August 6 and review Take Control activity.

Related Happenings

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577.

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
H score47 First: 31.07.2026 18:00 Last: 31.07.2026 18:00 Sources 1

How related: The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.

About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...

PAN-OS GlobalProtect CVE-2026-0257 exploitation wave

Exploitation Wave
H score18 First: 01.06.2026 11:30 Last: 01.06.2026 11:30 Sources 1

About this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....

Federal civilian executive branch agency hit by network compromise

Incident
H score21 First: 24.04.2026 23:34 Last: 24.04.2026 23:34 Sources 1

About this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...

FIRESTARTER malware on Cisco ASA and FTD devices

Malware Activity
H score33 First: 23.04.2026 15:00 Last: 23.04.2026 15:00 Sources 1

About this happening: CISA has published analysis of FIRESTARTER, a malware strain that enables remote access and control on Cisco Firepower and Secure Firewall devices, raising the ris...

Latest development: 24.04.2026 23:34

CISA, NCSC-UK, and Cisco detailed Firestarter persistence on Cisco Firepower and Secure Firewall devices running ASA or FTD software, attributing the backdoor to UAT-4356 and linking the activity to ArcaneDoor. The malware modifies CSP_MOUNT_LIST, stores a copy in /opt/cisco/platform/logs/var/log/svc_samcore.log, restores itself to /usr/bin/lina_cs, and relaunches after termination or reboot; Cisco recommends reimaging and upgrading to fixed releases, or using a cold restart only if reimaging is not possible.

Timeline

  1. 04.08.2026 10:00 2 articles · 3d ago

    CISA adds CVE-2026-18577 to KEV after active exploitation

    Legal Policy Action Update

    CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.

    Show sources
  2. 03.08.2026 09:41 1 articles · 4d ago

    N-able investigates licensing errors and finds remote administrative access on N-central servers

    Detection Ioc Update

    N-able began investigating unusual licensing errors from on-premises N-central customers on July 31 and determined that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, exposing customer systems managed through those servers.

    Show sources
  3. 03.08.2026 09:41 3 articles · 4d ago

    N-able ships N-central 2026.3.1.7 after the first fix proves incomplete

    Mitigation Patch Update

    N-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version after finding an alternative way to exploit the same vulnerability that the earlier 2026.2 fix did not block. It said every customer should move to 2026.3.1.7 because upgrading to 2026.3 was no longer sufficient and versions before the emergency hotfix remained vulnerable.

    Show sources
  4. 03.08.2026 03:00 2 articles · 4d ago

    Huntress links N-central exploitation to one partner account and nine organisations

    Campaign Scope Update

    Huntress reported on August 3 that it had seen exploitation in one organisation in its customer base, later clarifying that the activity involved a self-hosted N-central instance within one partner account that reached nine organisations and one endpoint in each. Based on the evidence available, the post-compromise activity was limited to enumerating running processes before the attackers disconnected, and Huntress did not observe the Cloudflare installation activity described by N-able.

    Show sources