Critical

N-able addresses critical N-central vulnerabilities exploited by attackers

SCM feed for Latest
Actively Exploited

Overview

N-able has reported that attackers exploited two vulnerabilities in their N-central servers, specifically CVE-2026-18556 and CVE-2026-18577. These vulnerabilities allowed unauthorized users to bypass authentication and gain remote administrative access to the affected systems. This incident poses a significant risk to organizations using N-central, as it could lead to unauthorized control over server functions and access to sensitive data. Users of N-central should take immediate action to secure their servers, as the vulnerabilities are actively being exploited. The situation emphasizes the need for vigilance in monitoring and updating security measures to protect against such threats.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: N-central servers by N-able
  • Action Required: N-able recommends that users update their N-central servers to the latest version to mitigate the vulnerabilities.
  • Timeline: Newly disclosed

Original Article Summary

Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrative access to N-central servers.

Impact

N-central servers by N-able

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

N-able recommends that users update their N-central servers to the latest version to mitigate the vulnerabilities. Specific patch numbers or versions were not mentioned, but users should ensure they are running the most current software available.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability, Critical.

Related Coverage

Critical vulnerability in Rails Active Storage could lead to RCE

SCM feed for Latest

A serious vulnerability has been identified in the Rails Active Storage component, affecting versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1. This flaw particularly impacts systems using the libvips image processing library, potentially allowing attackers to execute remote code on vulnerable applications. Users and organizations utilizing these specific versions are at risk, as the vulnerability poses a significant security threat. It's crucial for developers to check their Active Storage versions and apply the necessary updates to protect their applications. Ignoring this issue could lead to severe consequences, including unauthorized access and data breaches.

Aug 3, 2026

INC Ransomware chains two SonicWall SMA 1000 zero-days in attacks

SCM feed for Latest

Recent attacks have seen the INC ransomware exploiting two zero-day vulnerabilities in SonicWall's SMA 1000 series. These vulnerabilities have raised concerns among organizations using these devices, as they could lead to unauthorized access and data breaches. SonicWall's SMA 1000 series is commonly used for secure remote access, making it a critical target for attackers. With the ransomware actively leveraging these exploits, organizations should be on high alert and prioritize securing their systems. It's essential for affected users to implement security measures as soon as possible to mitigate potential risks.

Aug 3, 2026

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

The Hacker News

Researchers have identified a series of malicious npm packages that are specifically targeting users of Alibaba developer tools. This attack involves a cross-platform remote access trojan (RAT) and is part of a broader software supply chain attack aimed at Chinese-speaking environments. One notable package among those discovered is 'lib-mtop,' which shares its name with a private Alibaba package, suggesting a deliberate attempt to deceive users. The implications of this attack are significant, as it could allow attackers to gain unauthorized access to sensitive systems and data. Users of Alibaba tools should be particularly vigilant and consider reviewing their package dependencies to ensure they are not using any compromised versions.

Aug 3, 2026

COLDCARD Seed Generation Flaw Linked to Nearly $89 Million Bitcoin Theft

Hackread – Cybersecurity News, Data Breaches, AI and More

According to Galaxy Research, a Bitcoin theft involving 1,367.05 BTC, valued at nearly $89 million, has been linked to weaknesses in seed generation by COLDCARD devices. The issue arises from the way these devices generate cryptographic seeds, which are crucial for securing Bitcoin wallets. Coinkite, the company behind COLDCARD, has stated that existing users cannot fix seeds that were generated before updates were implemented. This situation raises significant concerns about the security of users' funds, as those with affected devices may still be at risk of theft. The incident underscores the importance of regular updates and secure seed generation practices for cryptocurrency users.

Aug 3, 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The Hacker News

The INC Ransomware group has become a major threat by taking advantage of security vulnerabilities in SonicWall's Secure Mobile Access (SMA) 1000 series VPN appliances. Since early August 2026, the group has ramped up its operations, targeting multiple organizations and posting their information on a data leak site. This surge in activity is particularly concerning for businesses using these VPN appliances, as it puts sensitive data at risk. Researchers have linked the increased ransomware attacks directly to the recently disclosed flaws in the SonicWall products, emphasizing the urgent need for users to address these vulnerabilities. Organizations should be vigilant and take immediate steps to secure their systems against these attacks.

Aug 3, 2026

Chinese Actor Weaponizes DeepSeek AI Agent to Attack Security Firm

darkreading

A Chinese actor has been linked to a new cybersecurity incident involving the use of a DeepSeek AI agent. Researchers discovered that this AI model was targeting over 1,200 hosts with the aim of proxyjacking, a technique that allows attackers to use compromised systems to launch further attacks. The implications of this activity raise concerns about the security of numerous networks, as the compromised hosts could be used to mask the identity of attackers and increase the scale of future cyber operations. This incident not only highlights the evolving tactics of cybercriminals but also emphasizes the need for organizations to enhance their defenses against such sophisticated methods. As more actors adopt AI-driven strategies, the cybersecurity landscape may become increasingly challenging for defenders.

Aug 3, 2026