Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-able security patch release for CVE-2026-18577

Security Patch Release
First reported
Last updated
Happening score
H score 46
2 unique sources, 3 articles

Summary

Hide ▲

N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3.1.7 for all versions before 2026.3, after earlier investigation found remote administrative access on servers running 2026.1 and earlier. N-able says hosted deployments already received the update, while on-premises customers must install it manually. The company also provided IOCs including four IP addresses, Cloudflared, and svchost.exe in the users’ documents folder.

Related Happenings

N-able security patch release for CVE-2026-18576

Security Patch Release
H score48 First: 05.08.2026 18:51 Last: 05.08.2026 18:51 Sources 1

About this happening: N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urge...

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: N-able has confirmed that a limited number of customers have been affected by the exploitation activity.

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
H score47 First: 31.07.2026 18:00 Last: 31.07.2026 18:00 Sources 1

About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...

Arista VeloCloud Orchestrator security update for CVE-2026-16812

Security Patch Release
H score55 First: 28.07.2026 01:49 Last: 28.07.2026 01:49 Sources 1

About this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...

CISA BOD 26-04 patch directive for CVE-2026-16232

Public Sector Action
H score37 First: 23.07.2026 11:13 Last: 23.07.2026 11:13 Sources 1

About this happening: CISA added CVE-2026-16232 to its known exploited vulnerabilities catalog and ordered U.S. federal agencies to patch vulnerable SmartConsole instances by July 25*...

Timeline

  1. 03.08.2026 09:41 1 articles · 13d ago

    N-able begins investigating unusual N-central licensing errors

    Detection Ioc Update

    N-able began investigating after an unusual volume of licensing errors from on-premises N-central customers, and the investigation found that an attacker had remotely gained administrative access to servers running 2026.1 and earlier.

    Show sources
  2. 03.08.2026 09:41 4 articles · 13d ago

    N-able ships 2026.3.1.7 as the first unaffected N-central build

    Mitigation Patch Update

    N-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version, told customers that upgrading to 2026.3 was no longer sufficient, and required every N-central customer to move to 2026.3.1.7.

    Show sources