Find notable cyber news and cases, enriched with sources, timelines, and signals.

N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 49
3 unique sources, 8 articles

Summary

Hide ▲

CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation before the vendor’s emergency fix. N-able said the flaw stems from an incomplete patch path for CVE-2026-18556, and that 2026.3.1.7 is the first unaffected release after an alternate bypass left 2026.3 insufficient. CISA added the issue to KEV on August 5, 2026, and Microsoft later linked recent attacks to Storm-1175 likely exploiting CVE-2026-18577 before deploying StormEncryptor and using AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz.

Related Happenings

StormEncryptor ransomware deployment by Storm-1175

Malware Activity
H score40 First: 10.08.2026 20:42 Last: 10.08.2026 20:42 Sources 1

How related: Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.

About this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...

N-able N-central servers hit by network compromise

Incident
H score41 First: 03.08.2026 09:41 Last: 03.08.2026 09:41 Sources 1

How related: As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577.

About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...

Latest development: 04.08.2026 10:00

CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.

Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia

Campaign
H score47 First: 31.07.2026 18:00 Last: 31.07.2026 18:00 Sources 1

How related: The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.

About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...

PAN-OS GlobalProtect CVE-2026-0257 exploitation wave

Exploitation Wave
H score18 First: 01.06.2026 11:30 Last: 01.06.2026 11:30 Sources 1

About this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....

Federal civilian executive branch agency hit by network compromise

Incident
H score21 First: 24.04.2026 23:34 Last: 24.04.2026 23:34 Sources 1

About this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...

Timeline

  1. 04.08.2026 10:00 4 articles · 12d ago

    CISA adds CVE-2026-18577 to KEV after active exploitation

    Legal Policy Action Update

    CISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.

    Show sources
  2. 03.08.2026 09:41 1 articles · 13d ago

    N-able investigates licensing errors and finds remote administrative access on N-central servers

    Detection Ioc Update

    N-able began investigating unusual licensing errors from on-premises N-central customers on July 31 and determined that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, exposing customer systems managed through those servers.

    Show sources
  3. 03.08.2026 09:41 4 articles · 13d ago

    N-able ships N-central 2026.3.1.7 after the first fix proves incomplete

    Mitigation Patch Update

    N-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version after finding an alternative way to exploit the same vulnerability that the earlier 2026.2 fix did not block. It said every customer should move to 2026.3.1.7 because upgrading to 2026.3 was no longer sufficient and versions before the emergency hotfix remained vulnerable.

    Show sources
  4. 03.08.2026 03:00 2 articles · 14d ago

    Huntress links N-central exploitation to one partner account and nine organisations

    Campaign Scope Update

    Huntress reported on August 3 that it had seen exploitation in one organisation in its customer base, later clarifying that the activity involved a self-hosted N-central instance within one partner account that reached nine organisations and one endpoint in each. Based on the evidence available, the post-compromise activity was limited to enumerating running processes before the attackers disconnected, and Huntress did not observe the Cloudflare installation activity described by N-able.

    Show sources