Critical

Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

Help Net Security
Actively Exploited

Overview

Attackers are taking advantage of an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management solution used by managed service providers. This flaw allows unauthorized access to managed endpoints, posing significant risks to organizations relying on N-central for their IT operations. The vulnerability was first noticed on July 31, 2026, when N-able experienced an unusual spike in licensing issues among its on-premises customers, prompting an investigation by their engineering and security teams. Given the widespread use of N-central, this incident could potentially affect numerous businesses and their clients. Organizations using this software should act quickly to mitigate the risk of exploitation.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: N-able N-central (specific versions not mentioned)
  • Action Required: Organizations should immediately review their N-able N-central configurations and apply any available patches.
  • Timeline: Newly disclosed

Original Article Summary

Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered “On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not uncommon, but the volume was high and the engineering and security teams were engaged,” N-able shared. “On the morning of … More → The post Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) appeared first on Help Net Security.

Impact

N-able N-central (specific versions not mentioned)

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should immediately review their N-able N-central configurations and apply any available patches. It's also advised to implement additional security measures, such as monitoring for unusual access patterns and enforcing stricter authentication protocols.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Exploit, Vulnerability.

Related Coverage

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News

Researchers have identified a series of malicious npm packages that are specifically targeting users of Alibaba developer tools. This attack involves a cross-platform remote access trojan (RAT) and is part of a broader software supply chain attack aimed at Chinese-speaking environments. One notable package among those discovered is 'lib-mtop,' which shares its name with a private Alibaba package, suggesting a deliberate attempt to deceive users. The implications of this attack are significant, as it could allow attackers to gain unauthorized access to sensitive systems and data. Users of Alibaba tools should be particularly vigilant and consider reviewing their package dependencies to ensure they are not using any compromised versions.

Aug 3, 2026

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Hackread – Cybersecurity News, Data Breaches, AI and More

According to Galaxy Research, a Bitcoin theft involving 1,367.05 BTC, valued at nearly $89 million, has been linked to weaknesses in seed generation by COLDCARD devices. The issue arises from the way these devices generate cryptographic seeds, which are crucial for securing Bitcoin wallets. Coinkite, the company behind COLDCARD, has stated that existing users cannot fix seeds that were generated before updates were implemented. This situation raises significant concerns about the security of users' funds, as those with affected devices may still be at risk of theft. The incident underscores the importance of regular updates and secure seed generation practices for cryptocurrency users.

Aug 3, 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News

The INC Ransomware group has become a major threat by taking advantage of security vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances. Since early August 2026, the group has ramped up its operations, targeting multiple organizations and posting their information on a data leak site. This surge in activity is particularly concerning for businesses using these VPN appliances, as it puts sensitive data at risk. Researchers have linked the increased ransomware attacks directly to the recently disclosed flaws in the SonicWall products, emphasizing the urgent need for users to address these vulnerabilities. Organizations should be vigilant and take immediate steps to secure their systems against these attacks.

Aug 3, 2026

Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm

darkreading

A Chinese actor has been linked to a new cybersecurity incident involving the use of a DeepSeek AI agent. Researchers discovered that this AI model was targeting over 1,200 hosts with the aim of proxyjacking, a technique that allows attackers to use compromised systems to launch further attacks. The implications of this activity raise concerns about the security of numerous networks, as the compromised hosts could be used to mask the identity of attackers and increase the scale of future cyber operations. This incident not only highlights the evolving tactics of cybercriminals but also emphasizes the need for organizations to enhance their defenses against such sophisticated methods. As more actors adopt AI-driven strategies, the cybersecurity landscape may become increasingly challenging for defenders.

Aug 3, 2026

Visa to Acquire Fraud Intelligence Firm BioCatch for $2.4 Billion

SecurityWeek

Visa has announced plans to acquire BioCatch, a firm specializing in fraud intelligence, for $2.4 billion. This acquisition aims to enhance Visa's capabilities in fighting digital fraud, including account takeovers and scams, by utilizing BioCatch's behavioral and device intelligence technology. Financial institutions are increasingly targeted by cybercriminals, and Visa's investment reflects the growing need to bolster security measures in the payments industry. By integrating BioCatch's solutions, Visa hopes to provide better protection for its customers and improve trust in digital transactions. This move could have significant implications for how financial institutions manage fraud prevention going forward.

Aug 3, 2026

China-Linked Threat Actors Weaponize New Vulnerabilities in Under a Day

Infosecurity Magazine

Chinese threat actors have quickly exploited a newly discovered vulnerability known as React2Shell, taking less than a day to do so. This trend is concerning, as recent research indicates that 88% of vulnerabilities disclosed in the first half of 2026 were compromised within just 48 hours. This rapid exploitation poses a significant risk to organizations that may not have patched their systems in time. Companies using affected software must prioritize updates and security measures to defend against these swift attacks. The situation underscores the need for vigilance in monitoring and addressing vulnerabilities promptly to mitigate potential damage.

Aug 3, 2026