N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

N-able has issued a warning to its customers regarding active exploitation of an authentication bypass vulnerability, identified as CVE-2026-18577, affecting its N-central remote monitoring and management (RMM) platform. The flaw impacts both hosted and on-premises N-central servers.
The company released hotfix 2026.3.1.7 on Sunday, August 2nd, to address the security issue. This hotfix is crucial as the vulnerability affects all N-central versions prior to 2026.3. N-able initially disclosed on August 1st that it had detected active exploitation and launched an investigation, which subsequently uncovered additional security concerns across all N-central versions.
N-central is a widely used RMM platform by managed service providers (MSPs) and corporate IT departments for managing diverse systems and network devices. The compromise of these servers could allow attackers to extend their reach beyond N-able's direct customers.
For hosted deployments, the update has already been applied. However, customers operating on-premises instances are required to manually install the hotfix immediately. While N-able agents do not require immediate updates to mitigate CVE-2026-18577, the company recommends updating them for the latest fixes and features.
CVE-2026-18577 is understood to be the result of an incomplete patch for an earlier vulnerability, CVE-2026-18576. The prior flaw, described as an authentication bypass utilizing an alternate path or channel, affected all N-central versions up to 2026.1. Both vulnerabilities could be leveraged for administrative account takeover.
N-able has not released specific technical details about the vulnerability, nor has it provided information regarding the number of customers affected or compromised through CVE-2026-18577. However, the vendor has provided indicators of compromise (IoCs) on the hotfix download page.
These IoCs include four specific IP addresses, the presence of a registered service named "Cloudflared," and an instance of "svchost.exe" found within a user's documents folder. Customers who identify any of these indicators are strongly advised to contact N-able support immediately and engage their internal security teams.
The use of "Cloudflared" is particularly notable, as attackers frequently abuse this legitimate tunneling utility from Cloudflare to establish outbound tunnels. Such tunnels can expose compromised machines or provide remote access without necessitating the opening of inbound firewall ports.
N-able has urged customers to maintain vigilance and closely monitor their environments. The company has also committed to providing further updates as more information becomes available.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.