Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-able security patch release for CVE-2026-18577

Security Patch Release
First reported
Last updated
Happening score
H score 41
1 unique sources, 1 articles

Summary

Hide ▲

N-able released 2026.3.1.7 for N-central on August 2, making it the required build after the earlier 2026.3 guidance proved incomplete. The hotfix is tied to CVE-2026-18577 and the earlier CVE-2026-18556 path, both affecting pre-2026.3.1.7 systems. Hosted NCOD instances will be upgraded automatically, while self-hosted servers must be updated by the customer. N-able also told customers to review logs and hunt for persistence on managed endpoints if compromise is suspected.

Related Happenings

N-able N-central servers hit by network compromise

Incident
H score39 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.

About this happening: The N-able N-central management platform suffered a remote administrative compromise that let attackers reach managed customer endpoints and created persistence risk acros...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action
H score37 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...

SonicWall security patch release for CVE-2026-15409

Security Patch Release
H score54 First: 15.07.2026 00:23 Last: 15.07.2026 00:23 Sources 1

About this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...

TrendAI Trend Micro’s enterprise business security patch release for CVE-2026-34926

Security Patch Release
H score45 First: 22.05.2026 11:19 Last: 22.05.2026 11:19 Sources 1

About this happening: TrendAI released Apex One security updates after confirming a zero-day had been exploited in the wild, leaving on-premises installations at risk until patched....

Timeline

  1. 03.08.2026 09:41 1 articles · 3h ago

    N-able begins investigating unusual N-central licensing errors

    Detection Ioc Update

    N-able began investigating after an unusual volume of licensing errors from on-premises N-central customers, and the investigation found that an attacker had remotely gained administrative access to servers running 2026.1 and earlier.

    Show sources
  2. 03.08.2026 09:41 2 articles · 3h ago

    N-able ships 2026.3.1.7 as the first unaffected N-central build

    Mitigation Patch Update

    N-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version, told customers that upgrading to 2026.3 was no longer sufficient, and required every N-central customer to move to 2026.3.1.7.

    Show sources