CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
- С сайта: Vulnerability(cybersecuritynews.com)
- Вернуться к списку новостей
CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks
Author: AbinayaCISA has warned that attackers are actively exploiting a critical authentication bypass vulnerability in N-able N-central. Tracked as CVE-2026-18577, the flaw affects N-central servers running versions earlier than 2026.3.1.7.
N-central is a remote monitoring and management platform widely used by managed service providers to administer customer systems. Because the platform provides centralized access to many endpoint devices, a compromise could enable attackers to move across managed environments.
CVE-2026-18577 is classified as an authentication bypass vulnerability via an alternate path or channel, mapped to CWE-288. N-able said the issue resulted from an incomplete patch for CVE-2026-18556, a previously addressed security flaw.
N-able N-central Authentication Bypass Vulnerability Exploited
According to N-able, attackers exploited the vulnerability to obtain remote administrative access to affected N-central servers. After gaining control of the server, the threat actors used the platform’s Take Control feature to access systems managed through N-central.
The attackers then created a new Cloudflare Tunnel service. This provided them with a persistence mechanism, allowing continued access to the affected environment even after their original access to the N-central server was revoked.
N-able first observed increased licensing issues among on-premises N-central customers on July 31, 2026. On August 2, 2026, during its investigation, the company identified an additional exploitation method. The vendor released a hotfix for N-central 2026.3 and advised all customers to upgrade to version 2026.3.1.7 immediately.
CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 3, 2026. Federal civilian executive branch agencies must apply mitigations by August 6, 2026, under Binding Operational Directive 26-04.
CISA also advised organizations to assess internet exposure, follow vendor instructions, and discontinue use of the product if mitigations are unavailable.
N-able said only a limited number of customers have been identified as affected, and its support teams have contacted those organizations directly. However, the vendor cautioned that its investigation remains ongoing and that more indicators may emerge.
N-able identified the following IP addresses as associated with the attacks: 173[.]249[.]252[.]200, 87[.]249[.]138[.]34, 37[.]19[.]210[.]32, 37[.]153[.]90[.]88, 92[.]118[.]112[.]181, and 68[.]235[.]46[.]214.
The company also released a custom N-central service template to help administrators detect known indicators on Windows endpoints. N-able stressed that a clean scan does not prove an environment is unaffected.
Organizations should review logs, account activity, remote access sessions, newly created services, and Cloudflare Tunnel configurations.
Administrators should patch N-central systems without delay, enforce multi-factor authentication, audit privileged accounts, and monitor managed endpoints for unusual remote-control activity or persistence mechanisms.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now .
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news
Оригинальная версия на сайте:


