N-central authentication bypass authentication bypass flaw (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central that affects hosted and on-premises servers and was used in active exploitation before the vendor’s emergency fix. N-able said the flaw stems from an incomplete patch path for CVE-2026-18556, and that 2026.3.1.7 is the first unaffected release after an alternate bypass left 2026.3 insufficient. CISA added the issue to KEV on August 5, 2026, and Microsoft later linked recent attacks to Storm-1175 likely exploiting CVE-2026-18577 before deploying StormEncryptor and using AnyDesk, SimpleHelp, Advanced IP Scanner, and Mimikatz.
Related Happenings
StormEncryptor ransomware deployment by Storm-1175
Malware Activity
H score40
First: 10.08.2026 20:42
Last: 10.08.2026 20:42
Sources 1
How related:
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.
About this happening:
Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
StormEncryptor ransomware deployment by Storm-1175
Malware ActivityHow related: Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor.
About this happening: Storm-1175 is deploying StormEncryptor, a previously undocumented ransomware strain that appends .encrypted to encrypted files and drops !!!README_FIRST!!!.txt ran...
N-able N-central servers hit by network compromise
Incident
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
How related:
As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577.
About this happening:
N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
N-able N-central servers hit by network compromise
IncidentHow related: As of writing, N-able has not shared any details on the scale of the attacks, but acknowledged a "limited number of customers" were compromised through CVE-2026-18577.
About this happening: N-able N-central is part of an ongoing authentication-bypass compromise that let attackers gain remote administrative access and reach managed systems through Take C...
Latest development: 04.08.2026 10:00
CISA added CVE-2026-18577 in N-able N-central to the KEV catalog after reports of active exploitation, and N-able said a limited number of customers were compromised through the flaw. Successful exploitation can give attackers administrative access to vulnerable N-central servers and let them pivot through Take Control into managed endpoints.
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
Campaign
H score47
First: 31.07.2026 18:00
Last: 31.07.2026 18:00
Sources 1
How related:
The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.
About this happening:
The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
Knaithe / KnYuan AI-orchestrated exploitation campaign targeting internet-exposed infrastructure in Asia
CampaignHow related: The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan.
About this happening: The knaithe / KnYuan campaign is an AI-orchestrated exploitation activity tied to Hermes Agent and DeepSeek, with Unit 42 describing autonomous enumeration and...
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation Wave
H score18
First: 01.06.2026 11:30
Last: 01.06.2026 11:30
Sources 1
About this happening:
CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
PAN-OS GlobalProtect CVE-2026-0257 exploitation wave
Exploitation WaveAbout this happening: CVE-2026-0257 is a Palo Alto Networks PAN-OS GlobalProtect authentication bypass that enabled unauthenticated VPN access on affected portal and gateway components....
Federal civilian executive branch agency hit by network compromise
Incident
H score21
First: 24.04.2026 23:34
Last: 24.04.2026 23:34
Sources 1
About this happening:
A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Federal civilian executive branch agency hit by network compromise
IncidentAbout this happening: A federal civilian executive branch agency was compromised in an early September 2025 intrusion that left attackers with persistent access on Cisco Firepower and Sec...
Timeline
-
04.08.2026 10:00 4 articles · 12d ago
CISA adds CVE-2026-18577 to KEV after active exploitation
Legal Policy Action UpdateCISA added CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. The flaw is an incomplete patch for CVE-2026-18556 that can allow authentication bypass and account takeover in susceptible versions, and N-able said the issue is addressed in version 2026.3 HF1. Federal Civilian Executive Branch agencies were told to apply the fixes by August 6, 2026 and review N-central Take Control activity.
Show sources
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises — thehackernews.com — 04.08.2026 10:00
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited — thehackernews.com — 05.08.2026 10:40
- New StormEncryptor ransomware used by former Medusa affiliate — www.bleepingcomputer.com — 10.08.2026 20:42
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw — thehackernews.com — 10.08.2026 19:38
-
03.08.2026 09:41 1 articles · 13d ago
N-able investigates licensing errors and finds remote administrative access on N-central servers
Detection Ioc UpdateN-able began investigating unusual licensing errors from on-premises N-central customers on July 31 and determined that an attacker had remotely gained administrative access to servers running 2026.1 and earlier, exposing customer systems managed through those servers.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
-
03.08.2026 09:41 4 articles · 13d ago
N-able ships N-central 2026.3.1.7 after the first fix proves incomplete
Mitigation Patch UpdateN-able shipped build 2026.3.1.7 on August 2 as the first unaffected N-central version after finding an alternative way to exploit the same vulnerability that the earlier 2026.2 fix did not block. It said every customer should move to 2026.3.1.7 because upgrading to 2026.3 was no longer sufficient and versions before the emergency hotfix remained vulnerable.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able warns of N-central auth bypass flaw exploited in attacks — www.bleepingcomputer.com — 03.08.2026 20:00
- CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities — www.securityweek.com — 05.08.2026 12:44
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist — thehackernews.com — 08.08.2026 09:57
-
03.08.2026 03:00 2 articles · 14d ago
Huntress links N-central exploitation to one partner account and nine organisations
Campaign Scope UpdateHuntress reported on August 3 that it had seen exploitation in one organisation in its customer base, later clarifying that the activity involved a self-hosted N-central instance within one partner account that reached nine organisations and one endpoint in each. Based on the evidence available, the post-compromise activity was limited to enumerating running processes before the attackers disconnected, and Huntress did not observe the Cloudflare installation activity described by N-able.
Show sources
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete — thehackernews.com — 03.08.2026 09:41