Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-able N-central servers hit by network compromise

Incident
First reported
Last updated
Happening score
H score 39
1 unique sources, 1 articles

Summary

Hide ▲

The N-able N-central management platform suffered a remote administrative compromise that let attackers reach managed customer endpoints and created persistence risk across downstream environments. N-able said the abuse started with an authentication bypass, while Huntress said activity in one partner account reached nine organisations and was so far limited to process enumeration. N-able also warned that malicious Cloudflared services on endpoints could survive revocation of access, so remediation requires endpoint hunting as well as server recovery.

Related Happenings

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
H score40 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: CVE-2026-18577 affects N-central builds prior to 2026.3.1.7.

About this happening: CVE-2026-18577 kept N-able N-central vulnerable in builds before 2026.3.1.7, leaving an authentication bypass that could expose remote administrative access to...

N-able security patch release for CVE-2026-18577

Security Patch Release
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.

About this happening: N-able released 2026.3.1.7 for N-central on August 2, making it the required build after the earlier 2026.3 guidance proved incomplete. The hotfix is tied to *...

TaskWeaver and Djinn Stealer delivered through abused SimpleHelp RMM tools

Malware Activity
H score36 First: 30.06.2026 18:34 Last: 30.06.2026 18:34 Sources 1

About this happening: The abuse of SimpleHelp RMM turned a trusted support channel into a malware delivery path for TaskWeaver and Djinn Stealer, expanding attacker reach into managed netwo...

CISA FortiBleed mitigation guidance

Advisory/Mitigation
H score67 First: 19.06.2026 09:47 Last: 19.06.2026 09:47 Sources 1

About this happening: CISA issued mitigation guidance for FortiBleed, urging operators of internet-accessible Fortinet devices to harden exposed FortiGate and VPN environments after a *...

Phantom Mantis shifts The Gentlemen into an independent ransomware partnership program

Threat Actor Meta
H score24 First: 11.06.2026 19:50 Last: 11.06.2026 19:50 Sources 1

About this happening: Phantom Mantis moved The Gentlemen from dependence on other ransomware ecosystems into an independent partnership program, expanding its operational autonomy and affil...

Timeline

  1. 03.08.2026 09:41 1 articles · 3h ago

    N-able begins investigating unusual licensing errors on N-central servers

    Initial Disclosure

    N-able began investigating after an unusual volume of licensing errors from on-premises customers and found that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, giving access to customer systems managed through those servers.

    Show sources
  2. 03.08.2026 09:41 1 articles · 3h ago

    N-able ships build 2026.3.1.7 after finding an alternate N-central bypass

    Mitigation Patch Update

    N-able said its earlier fix was incomplete, identified CVE-2026-18577, and shipped build 2026.3.1.7 as the first unaffected version. The company said N-central builds prior to 2026.3.1.7 were vulnerable, and Finland's national cyber security centre said an August 2 advisory found all versions available before the emergency hotfix were vulnerable.

    Show sources
  3. 03.08.2026 09:41 2 articles · 3h ago

    Huntress reports limited post-compromise activity and publishes N-central attacker domains

    Technical Analysis Update

    N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and used Take Control and Cloudflare tunnels to persist on managed endpoints. Huntress said a rapid response published August 3 initially saw exploitation at one organisation in its customer base, published three attacker domains, and found the post-compromise activity it had seen was limited to enumerating running processes before the attackers disconnected.

    Show sources