Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 40
1 unique sources, 1 articles

Summary

Hide ▲

CVE-2026-18577 kept N-able N-central vulnerable in builds before 2026.3.1.7, leaving an authentication bypass that could expose remote administrative access to managed customer systems. The flaw remained exploitable after N-able's first fix for CVE-2026-18556, widening the affected build range beyond the earlier remediation. N-able said 2026.3.1.7 is the first unaffected version. Affected customers were told to upgrade and check for persistence after compromise.

Related Happenings

N-able N-central servers hit by network compromise

Incident
H score39 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.

About this happening: The N-able N-central management platform suffered a remote administrative compromise that let attackers reach managed customer endpoints and created persistence risk acros...

Warlock ransomware post-exploitation tooling upgrades

Malware Activity
H score38 First: 17.03.2026 17:36 Last: 17.03.2026 17:36 Sources 1

About this happening: The Warlock ransomware group has upgraded its post-exploitation toolset with BYOVD, TightVNC, and Yuze, making intrusions harder to detect and interrupt. In an obs...

Timeline

  1. 03.08.2026 09:41 1 articles · 3h ago

    N-able investigates licensing errors and finds remote administrative access on N-central servers

    Detection Ioc Update

    N-able began investigating unusual licensing errors from on-premises N-central customers on July 31 and determined that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, exposing customer systems managed through those servers.

    Show sources
  2. 03.08.2026 09:41 1 articles · 3h ago

    N-able ships N-central 2026.3.1.7 after the first fix proves incomplete

    Mitigation Patch Update

    N-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version after finding an alternative way to exploit the same vulnerability that the earlier 2026.2 fix did not block. It said every customer should move to 2026.3.1.7 because upgrading to 2026.3 was no longer sufficient and versions before the emergency hotfix remained vulnerable.

    Show sources
  3. 03.08.2026 03:00 2 articles · 10h ago

    Huntress links N-central exploitation to one partner account and nine organisations

    Campaign Scope Update

    Huntress reported on August 3 that it had seen exploitation in one organisation in its customer base, later clarifying that the activity involved a self-hosted N-central instance within one partner account that reached nine organisations and one endpoint in each. Based on the evidence available, the post-compromise activity was limited to enumerating running processes before the attackers disconnected, and Huntress did not observe the Cloudflare installation activity described by N-able.

    Show sources