ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
N-able N-central exposed to auth bypass; CVE-2026-18577 fix not complete
Source headline: N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Threat level
Critical
Signal strength
85/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
N-able says attackers exploited an authentication bypass in N-central to obtain remote administrative access. From those compromised N-central servers, attackers could reach and interact with customer systems managed through the platform. The company states its initial remediation did not fully address the issue. CVE-2026-18577 impacts N-central builds prior to 2026.3.1.7. N-able released build 2026.3.1.7 on August 2 as the first unaffected version, so operators should upgrade promptly.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Open original source