N-able security patch release for CVE-2026-18576
Security Patch Release
Summary
Hide ▲
Show ▼
N-able released an emergency hotfix for CVE-2026-18576 in N-central, closing an authentication flaw that let attackers hijack administrative accounts. The company urged customers to install the fix on all versions before 2026.3 after the issue was reported as actively exploited. The out-of-band update addresses a weakness that had already been patched once but remained usable by threat actors.
Related Happenings
N-able security patch release for CVE-2026-18577
Security Patch Release
H score41
First: 03.08.2026 09:41
Last: 03.08.2026 09:41
Sources 1
About this happening:
N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
N-able security patch release for CVE-2026-18577
Security Patch ReleaseAbout this happening: N-able is warning that CVE-2026-18577 is being actively exploited against N-central on both hosted and on-premises servers. The vendor released hotfix 2026.3...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch Release
H score55
First: 28.07.2026 01:49
Last: 28.07.2026 01:49
Sources 1
About this happening:
Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
Arista VeloCloud Orchestrator security update for CVE-2026-16812
Security Patch ReleaseAbout this happening: Arista patched CVE-2026-16812, a maximum-severity 10.0 OS command injection flaw in on-premises VeloCloud Orchestrator (VCO), after confirming it is actively...
SonicWall security patch release for CVE-2026-15409
Security Patch Release
H score54
First: 15.07.2026 00:23
Last: 15.07.2026 00:23
Sources 1
About this happening:
SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
SonicWall security patch release for CVE-2026-15409
Security Patch ReleaseAbout this happening: SonicWall released hotfix security updates for SMA1000 appliances after confirming active exploitation of CVE-2026-15409 and CVE-2026-15410. The fixes are availabl...
Dify security patch release for CVE-2026-41947
Security Patch Release
H score34
First: 22.06.2026 19:13
Last: 22.06.2026 19:13
Sources 1
About this happening:
Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Dify security patch release for CVE-2026-41947
Security Patch ReleaseAbout this happening: Dify shipped version 1.14.2 to fix most of the DifyTap vulnerabilities, closing cross-tenant paths that could expose AI chats, uploaded files, and internal API...
Ubiquiti UniFi OS security updates (multiple vulnerabilities)
Security Patch Release
H score28
First: 22.05.2026 15:00
Last: 22.05.2026 15:00
Sources 1
About this happening:
Ubiquiti released security updates for UniFi OS to close five vulnerabilities, including three maximum-severity flaws that could let remote attackers without...
Ubiquiti UniFi OS security updates (multiple vulnerabilities)
Security Patch ReleaseAbout this happening: Ubiquiti released security updates for UniFi OS to close five vulnerabilities, including three maximum-severity flaws that could let remote attackers without...
Latest development: 24.06.2026 15:32
CISA warned that threat actors were targeting CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 in Ubiquiti UniFi OS devices after the flaws were patched in UniFi OS Server 5.0.8, and multiple users reported that the bugs were exploited in the wild, likely as zero-days, to create rogue administrator accounts named John Sim.
Timeline
-
05.08.2026 18:51 1 articles · 1h ago
N-able warns customers about actively exploited CVE-2026-18576 in N-central
Initial DisclosureN-able warned customers on August 1 that CVE-2026-18576 in N-central was being actively exploited. The flaw lets attackers hijack administrative accounts without authentication in the remote monitoring and management platform before version 2026.3.
Show sources
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51
-
05.08.2026 18:51 2 articles · 1h ago
N-able releases an emergency hotfix for CVE-2026-18576 in N-central
Mitigation Patch UpdateN-able released an emergency hotfix for CVE-2026-18576 and urged customers to install it on all versions of N-central before 2026.3. The earlier vendor patch was insufficient, leaving the authentication flaw usable by threat actors.
Show sources
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws — www.bleepingcomputer.com — 05.08.2026 18:51