Home / Aug 04, 2026 / Story
0
#3 The Hacker News general August 03, 2026 at 06:41 UTC

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

By [email protected] (The Hacker News)

AI Summary

N-able's authentication bypass vulnerability CVE-2026-18577 in N-central RMM servers was actively exploited after the vendor's initial patch proved incomplete, allowing attackers to gain remote administrative access and pivot to customer-managed systems. N-able shipped the first unaffected build (2026.3.1.7) on August 2, 2026. The incident is particularly severe because N-central serves as a managed service provider platform, meaning a single compromised server can expose downstream client environments at scale.

Relevance score: 86.0/100

# More from August 04