The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following confirmed active exploitation. Tracked as CVE-2026-18577 (CVSS 8.2), the flaw is an authentication bypass that allows account takeover in susceptible versions of the remote monitoring and management (RMM) platform. It stems from incomplete patching of a related vulnerability, CVE-2026-18556, and has been addressed in N-central version 2026.3 HF1.
Successful exploitation enables remote attackers to gain administrative access to N-central servers, then abuse the built-in Take Control feature to pivot into managed endpoints and deploy persistence mechanisms. CISA warns that Federal Civilian Executive Branch (FCEB) agencies must apply fixes by August 6, 2026, and review N-central Take Control activity.
N-able has shared indicators of compromise, including a suspicious file named “svchost.exe” in device users’ documents folders, a registered service named “Cloudflared” (a legitimate Cloudflare tunneling utility abused for covert connections), and inbound connections from four IP addresses: 173.249.252[.]200, 87.249.138[.]34, 37.19.210[.]32, and 68.235.46[.]214. These IPs are Mullvad or NordVPN exit nodes.
Security firm Huntress observed threat actors exploiting the flaw across multiple organizations, though the activity has not been publicly attributed to a known group. Post-exploitation patterns include high-level reconnaissance targeting domain controllers, enumerating running processes, and lateral movement. In one case, the attacker used the default username “MSP Support” to make a malicious connection via Take Control from IP 173.249.252[.]200.
N-able acknowledged a “limited number of customers” were compromised but has not disclosed the full scale. This incident follows the weaponization of two other N-central flaws (CVE-2025-8875 and CVE-2025-8876) roughly a year earlier, underscoring continued targeting of RMM platforms for persistent network access.
CVEs: CVE-2026-18577, CVE-2026-18556, CVE-2025-8875, CVE-2025-8876, CVE-2026-50522
Companies: CISA, N-able, Huntress, Cloudflare, Mullvad VPN, NordVPN
Products: N-able N-central, Take Control, Cloudflared
Original source: thehackernews.com