Critical

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

Security Affairs
Actively Exploited

Overview

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a significant vulnerability, tracked as CVE-2026-18577, to its Known Exploited Vulnerabilities catalog. This flaw affects N-able N-central, a platform used for IT management and monitoring. With a CVSS score of 8.2, the vulnerability allows attackers to bypass authentication, potentially granting them unauthorized access to sensitive systems. Organizations using N-able N-central should be particularly vigilant as this vulnerability poses a serious risk to their operations and data security. It's crucial for affected users to take immediate action to mitigate any potential exploitation.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: N-able N-central, versions not specified.
  • Action Required: Organizations should apply any available patches from N-able for the N-central platform.
  • Timeline: Newly disclosed

Original Article Summary

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an […]

Impact

N-able N-central, versions not specified.

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should apply any available patches from N-able for the N-central platform. Additionally, they should review their authentication processes and consider implementing stricter access controls to mitigate the risk of exploitation.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to CVE, Vulnerability.

Related Coverage

First Malware Built Specifically for Car Head Units Fuels Botnet

SecurityWeek

Kaspersky researchers have identified a new type of malware specifically designed for car head units, which are the infotainment systems found in vehicles. This malware has been linked to the BadBox botnet, a network that has already compromised millions of devices. The malware's targeting of car systems raises significant concerns about the security of vehicle technology, as it could potentially allow attackers to control various functions of the car or access sensitive data. This incident emphasizes the growing vulnerability of modern vehicles to cyber threats, highlighting a need for stronger security measures in automotive technology. Car manufacturers and users alike should be aware of this emerging threat and take precautions to safeguard their systems.

Aug 25, 2026

Police arrests dozens of suspects in global cybercrime crackdown

BleepingComputer

In a significant global effort against cybercrime, law enforcement agencies from 22 countries collaborated to identify 263 suspects and arrest 58 individuals tied to criminal networks primarily based in Africa. This crackdown is part of a broader initiative to combat organized cybercrime, which has been a growing concern worldwide. The arrested suspects are believed to be involved in various cybercrimes, including fraud and identity theft, affecting numerous victims across different regions. By targeting these networks, authorities aim to disrupt the operations of these cybercriminals and protect potential victims from future attacks. This operation underscores the need for international collaboration in tackling cyber threats that span multiple borders.

Aug 25, 2026

Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown

Infosecurity Magazine

Despite the takedown of its original infrastructure in July, the WeedHack malware continues to target Minecraft players through fake client downloads. This malware is particularly concerning as it can compromise user accounts and potentially lead to further security breaches. The ongoing distribution of WeedHack highlights the resilience of cybercriminals and their ability to adapt after losing access to their previous systems. Players who download these malicious clients are at risk, as the malware can steal sensitive information. This situation serves as a reminder for gamers to be cautious about where they download software and to be aware of the risks associated with unofficial game clients.

Aug 25, 2026

Unpatched Zimbra servers are falling to CVE-2026-73570 attacks

Help Net Security

At least 274 Zimbra servers have been compromised by attackers exploiting a vulnerability identified as CVE-2026-73570. This particular flaw is a code injection issue in the Zimbra Collaboration Suite (ZCS), which is widely used by organizations that prefer to manage their own data instead of relying on more expensive services like Microsoft 365 or Google Workspace. The vulnerability was patched by Synacor in version 10.1.20 of ZCS, released on July 20, 2026. However, many instances remain unpatched, leaving them vulnerable to exploitation. This incident highlights the risks associated with not keeping software updated, especially for platforms that handle sensitive communication and collaboration.

Aug 25, 2026

Silent Patches Don’t Stop Attackers—They Blind Defenders

SecurityWeek

The article discusses the issue of silent patches, which are updates made to software to fix vulnerabilities without publicly disclosing the details. While these patches can help secure systems, they also create a problem for defenders. Attackers can exploit these vulnerabilities without defenders knowing the full context of the risks they face. This lack of transparency can lead to misprioritization of security efforts, leaving organizations vulnerable. The piece emphasizes the need for better communication about vulnerabilities and updates to ensure that defenders have the information they need to protect against potential exploits.

Aug 25, 2026

ReliaQuest Rejects Compromise Claims After ShinyHunters Incident

Infosecurity Magazine

ReliaQuest has addressed a recent social engineering attack associated with the hacking group ShinyHunters. The company clarified that while there were attempts to compromise its systems, the attackers did not succeed in breaching their defenses. This incident serves as a reminder of the growing threat posed by social engineering tactics, where attackers manipulate individuals into divulging confidential information. Despite the denial of a successful compromise, the event raises concerns about the effectiveness of security measures and the importance of employee awareness training. Companies must remain vigilant against such tactics to protect sensitive data and maintain trust with their clients.

Aug 25, 2026