#3
The Hacker News
general
August 03, 2026 at 06:41 UTC
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
By [email protected] (The Hacker News)
AI Summary
N-able's authentication bypass vulnerability CVE-2026-18577 in N-central RMM servers was actively exploited after the vendor's initial patch proved incomplete, allowing attackers to gain remote administrative access and pivot to customer-managed systems. N-able shipped the first unaffected build (2026.3.1.7) on August 2, 2026. The incident is particularly severe because N-central serves as a managed service provider platform, meaning a single compromised server can expose downstream client environments at scale.
Relevance score: 86.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →