LIVE · cybersecurity feed
Live wire
CVE-2026-66066 · KindaRails2Shell threatens Ruby on Rails apps (CVE-2026-66066)Rails patches critical Active Storage flaw with RCE potentialCVE-2026-48449 · Adobe fixed a maximum-severity vulnerability flaw in Campaign ClassicRuby on Rails Patches Critical VulnerabilityHackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer SitesHijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance MalwareCaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theftHollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law FirmCVE-2026-33017 · Chinese Hacker Uses DeepSeek AI to Orchestrate Vulnerability ExploitsThis month in security with Tony Anscombe – July 2026 edition
CVE-2026-18577

N-able warns of N-central auth bypass flaw exploited in attacks

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

zeroday.news · 3h ago

N-able has issued a warning to its customers regarding active exploitation of an authentication bypass vulnerability, identified as CVE-2026-18577, affecting its N-central remote monitoring and management (RMM) platform. The flaw impacts both hosted and on-premises N-central servers.

The company released hotfix 2026.3.1.7 on Sunday, August 2nd, to address the security issue. This hotfix is crucial as the vulnerability affects all N-central versions prior to 2026.3. N-able initially disclosed on August 1st that it had detected active exploitation and launched an investigation, which subsequently uncovered additional security concerns across all N-central versions.

N-central is a widely used RMM platform by managed service providers (MSPs) and corporate IT departments for managing diverse systems and network devices. The compromise of these servers could allow attackers to extend their reach beyond N-able's direct customers.

For hosted deployments, the update has already been applied. However, customers operating on-premises instances are required to manually install the hotfix immediately. While N-able agents do not require immediate updates to mitigate CVE-2026-18577, the company recommends updating them for the latest fixes and features.

CVE-2026-18577 is understood to be the result of an incomplete patch for an earlier vulnerability, CVE-2026-18576. The prior flaw, described as an authentication bypass utilizing an alternate path or channel, affected all N-central versions up to 2026.1. Both vulnerabilities could be leveraged for administrative account takeover.

N-able has not released specific technical details about the vulnerability, nor has it provided information regarding the number of customers affected or compromised through CVE-2026-18577. However, the vendor has provided indicators of compromise (IoCs) on the hotfix download page.

These IoCs include four specific IP addresses, the presence of a registered service named "Cloudflared," and an instance of "svchost.exe" found within a user's documents folder. Customers who identify any of these indicators are strongly advised to contact N-able support immediately and engage their internal security teams.

The use of "Cloudflared" is particularly notable, as attackers frequently abuse this legitimate tunneling utility from Cloudflare to establish outbound tunnels. Such tunnels can expose compromised machines or provide remote access without necessitating the opening of inbound firewall ports.

N-able has urged customers to maintain vigilance and closely monitor their environments. The company has also committed to providing further updates as more information becomes available.

vulnerability
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Galaxy Research linked a suspected Bitcoin theft of 1,367.05 BTC to weak COLDCARD seeds. Coinkite says updates cannot repair seeds already generated on devices.

vulnerability

More on the OpenAI Agent’s Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the ExploitGym benchmark, which tasks an AI agent with finding and exploiting software vulnerabilities. OpenAI ran this on its own infrastructure, and the ExploitGym maintainers and their infrastructure had no involvement in the deployment or

malware

Fake Roblox Xeno script launcher pushes infostealer, RAT malware

Fake Xeno Executor installers are infecting unsuspecting Roblox players with malware that provides remote access and steals sensitive information. [...]

malware

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments. One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

ai

AI slop pollutes the CVE pipeline with fake vulns

With NIST still buried under its backlog, expect AI-generated bogus reports to continue

security

Why Bitcoin Businesses Are Moving to Dedicated VPS Infrastructure

A Bitcoin business rarely runs a simple website. Payment processors, exchanges, wallet services, blockchain analytics products and Lightning…