CISA Updates KEV Catalog With N-able N-central Authentication Bypass Vulnerability

Published:

US. Cybersecurity and Infrastructure Security Agency (CISA) has added a high severity vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following confirmed reports of active exploitation targeting customers. The flaw, tracked as CVE 2026 18577 with a CVSS score of 8.2, is described as an incomplete patch for the previously disclosed CVE 2026 18556 and allows authentication bypass and account takeover in vulnerable versions of N-able N-central. The issue has been resolved in version 2026.3 HF1. According to CISA, successful exploitation enables remote attackers to bypass authentication controls, obtain administrative access to vulnerable N-central servers, and misuse the built in Take Control feature to move into managed endpoints while establishing persistent access within affected environments. Following the confirmed exploitation, CISA has directed Federal Civilian Executive Branch agencies to apply the available security updates by August 6, 2026, and review Take Control activity across their environments.

N-able has also released guidance to help organizations detect potential compromise by identifying several indicators of compromise associated with the attacks. The company advised administrators to inspect device user document folders for a suspicious file named “svchost.exe” and to look for a registered Windows service named “Cloudflared.” Although Cloudflared is a legitimate tunneling utility developed by Cloudflare, it has frequently been abused by threat actors to establish covert outbound connections and conceal malicious network activity within legitimate traffic. Organizations have also been advised to monitor inbound connections originating from four IP addresses that investigators associated with observed attacks. While the activity has not yet been attributed to a specific threat actor or cybercriminal group, cybersecurity company Huntress confirmed that multiple organizations have already been targeted through exploitation of the vulnerability. At this stage, researchers indicated there is no evidence that the attacks have expanded into a broad indiscriminate campaign affecting all exposed systems.

According to Huntress, attackers exploiting CVE 2026 18577 have demonstrated a consistent pattern of post exploitation activity after gaining unauthorized access. Researchers observed threat actors conducting reconnaissance to identify critical infrastructure such as domain controllers before enumerating running processes on compromised systems and disconnecting. In several incidents, attackers later moved laterally across additional hosts within affected organizations after establishing their initial foothold. Huntress also identified at least one case in which attackers connected through the default N-central username “MSP Support” from the IP address 173.249.252.200 during a legitimate Take Control session. The four IP addresses identified by investigators correspond to VPN exit nodes operated by NordVPN and Mullvad VPN services. Huntress noted that substantial malicious traffic had been observed from both 87.249.138.34 and 37.19.210.32, adding that the latter address had previously been associated with brute force attacks, spam campaigns, and other malicious activities before the current incidents. These observations suggest attackers are leveraging widely available VPN infrastructure to obscure the origin of their operations while maintaining remote access to compromised environments.

N-able has acknowledged that a limited number of customers were compromised through exploitation of CVE 2026 18577, although the company has not disclosed the full scale of the incidents. The attacks highlight the continued interest of threat actors in targeting remote monitoring and management platforms because of their ability to provide privileged access to enterprise environments and managed endpoints. The latest exploitation also comes almost exactly one year after two other vulnerabilities affecting N-able N-central, tracked as CVE 2025 8875 and CVE 2025 8876, were used in limited attacks targeting on premises deployments. With the inclusion of CVE 2026 18577 in the KEV catalog, organizations using N-able N-central are encouraged to apply the latest security updates, review administrative activity, investigate the published indicators of compromise, and verify that unauthorized access has not occurred within their environments.

Source

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem. 

Related articles

spot_img