ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

highExploit / PoC exploited in the wildimportance 78CVE-2026-18577CVE-2026-18556
AI summary · glm-5.3-flash

N-able shipped a second N-central hotfix as attackers actively exploit authentication bypass CVE-2026-18577, attributed to ransomware group Storm-1175.

N-able released Hotfix 2 (N-central 2026.3.1.10) to counter ongoing exploitation of CVE-2026-18577, an authentication bypass that evades the patch for the earlier CVE-2026-18556; exploitation was first detected on August 1, 2026. Post-exploitation includes using the Take Control feature to reach managed endpoints, registering a Cloudflare tunnel service for persistence, creating a 'veeam' domain account, resetting admin passwords, and disabling Microsoft and Sophos security tooling. Microsoft analysts link the activity to Storm-1175, which now deploys a new StormEncryptor ransomware strain instead of Medusa, often reaching data exfiltration and ransomware within days. Sophos and Huntress expanded the IOCs and warned that partners who patched late should treat environments as potentially compromised.

  • CVE-2026-18577 is a patch bypass of the previously fixed CVE-2026-18556
  • Attackers register Cloudflare tunnel services for persistence on managed endpoints
  • Storm-1175 linked; switched from Medusa to new StormEncryptor ransomware
  • Hotfix 2 blocks entry but does not evict attackers already present
  • Delayed patchers should review all accounts, privileges, and activity

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-18556
Authentication Bypass (Alternate Path/Channel) in N-able N-central

N-able's N-central RMM platform contains an authentication bypass (CWE-288) in which an alternate path or channel allows requests to skip the normal authentication check. An unauthenticated attacker can trigger it by sending requests through that alternate path without valid credentials, gaining unauthorized access to the N-central management interface; because N-central is remote monitoring and management software run by managed service providers, such access can expose management functions across downstream customer environments. N-able N-central deployments are affected; the available data does not specify affected version ranges or fixed builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-08-04, confirming exploitation in the wild, with a high EPSS of 40.2% (99th percentile), no CVSS score yet, no public PoC, and undetermined ransomware use; related reporting describes a recent string of N-central hotfixes, including fixes for unauthenticated remote code execution.

Do: Apply N-able's hotfix for N-central immediately per the vendor's instructions, since the flaw is in CISA KEV and BOD 26-04 applies (for cloud-hosted N-central, apply mitigations per BOD 26-04 or discontinue use if mitigations are unavailable). Until patched, restrict internet exposure of the N-central server to trusted management networks and review authentication logs for unexpected access, following CISA's forensics triage guidance. Check the vendor advisory for the exact fixed build, as the available data does not list affected or fixed version numbers.

8.240% KEV
  • N-able N-central
largeon the order of tens of thousands of N-central server instances (estimate; exact counts not in available data)
CVE-2026-18577
Authentication Bypass and Account Takeover in N-able N-central (Incomplete Patch)

CVE-2026-18577 is an authentication bypass (CWE-288) in N-able's N-central RMM platform caused by an incomplete patch for the earlier vulnerability CVE-2026-18556. Because the original fix can be bypassed via an alternate path or channel, a remote, unauthenticated attacker needs no privileges or user interaction, though the attack requires meeting exploit-specific conditions (high attack complexity, CVSS 4.0: 8.2 High). Successful exploitation lets the attacker bypass authentication and take over N-central accounts, gaining high-impact access to the management console with limited direct effects on downstream services. All N-central versions through 2026.3.1 are affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2026-08-03, EPSS estimates a 54.1% chance of exploitation within 30 days (99th percentile), and news reports say attackers kept exploiting it even as N-able shipped successive hotfixes; ransomware use is currently unknown.

Do: Upgrade N-central to a fixed release or hotfix newer than 2026.3.1 following N-able's advisory — the vendor has issued multiple successive hotfixes for this and related N-central flaws, so verify you are on the latest build. Because the flaw is on CISA's KEV, federal and BOD 26-04-bound organizations must apply vendor mitigations promptly or discontinue use of the product if patching is unavailable. Limit internet exposure of N-central portals and review accounts for signs of takeover or unauthorized access.

8.254% KEV
  • N-able N-central all versions through 2026.3.1 (incomplete patch for CVE-2026-18556)
moderate≈1,000–10,000 internet-exposed N-central server instances (estimate from public internet scans; total on-prem deployments likely higher, with millions of…
Full article785 words · extracted from helpnetsecurity.com · click to collapse

To help customers fend off ongoing attacks, N-able released a second security hotfix for N‑central, its monitoring and management (RMM) solution popular with managed service providers (MSPs).

“Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures to further protect you and your customers,” the company said, and shared additional indicators of compromise observed in attacks.

A second hotfix to “expand protections”

Earlier this month, N‑able released N-central version 2026.3.1.7 (i.e., 2026.3 Hotfix 1), which patches an authentication bypass vulnerability (CVE-2026-18577) the company detected being exploited by attackers.

“On July 31, 2026, N‑able’s Adlumin MDR solution detected unusual activity within a customer’s environment, leading to the discovery of a threat actor actively exploiting a zero-day vulnerability in an N‑central server,” the company explained on Thursday.

CVE-2026-18577 was assigned to a patch bypass of the previously fixed CVE-2026-18556: a threat actor obviously found a variation that evades the previous patch’s specific checks and has been using it to compromise N-central instances and gain access to managed endpoints.

N-able did not say whether the threat actor found a way around the first hotfix, just that they are “proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques.”

“It is highly recommended that all partners upgrade to [N-central version 2026.3.1.10, i.e., 2026.3 Hotfix 2] ASAP,” the company said, and added that upgrading the agents on the managed devices is recommended (though not necessary) to protect customers from CVE-2026-18577.

Organizations using hosted N-central don’t have to update, as the hotfix has been applied already.

How the attackers operate post-exploitation

N-able says that once the threat actor exploits the vulnerability, they use the legitimate Take Control feature and connect to managed endpoints, where they register a new service for a CloudFlare tunnel for persistence.

The company first detected exploitation of CVE-2026-18577 on August 1, 2026, and shared a list of 6 IP addresses associated with the attacks.

Sophos says that the threat actor created a new domain account named “veeam” and reset the passwords of several existing domain administrator accounts, enumerated other existing accounts, installed additional remote-access tools, and disabled security software made by Microsoft and Sophos by leveraging an EDR-evasion tool.

The company expanded N-able’s initial list of indicators of compromise with four additional IP addresses and domain names of C2 and TacticalRMM servers.

Huntress researchers, after detecting exploitation on one of its customers’ N-central environments, shared additional insight into the actions performed by the threat actor.

According to them, the threat actor targeted key servers (typically Domain Controllers), enumerated process on a compromised system (before disconnecting), and later moved quickly across multiple hosts in impacted organizations’ environments.

“We are now seeing threat actors targeting the flaw across multiple organizations, though we are not yet seeing evidence that this has become a broad, indiscriminate campaign across our partner base,” they noted.

Microsoft’s threat analysts believe that the threat actor behind these attacks might be Storm-1175, a financially motivated group known for operating high-velocity ransomware campaigns, usually by exploiting known, recently patched vulnerabilities.

They say that the group has switched from deploying the Medusa ransomware to using a new ransomware strain called StormEncryptor.

“In this new activity, Storm-1175’s post-compromise behavior includes abuse of remote monitoring and management tools AnyDesk or SimpleHelp, Advanced IP Scanner for discovery, and LSASS dumping using Mimikatz,” they shared.

“This threat actor is known to rapidly move from initial access to data exfiltration and ransomware deployment, often within a few days. Organizations are urged to monitor for Storm-1175 activity and apply security patches as soon as possible.

UPDATE (August 12, 2026, 02:50 a.m. ET):

N-able has cleared up that Hotfix 2 blocks a related attack path (along with delivering hardening measures), and has expanded the list of indicators of compromise to include indicators flagged by several cybersecurity firms.

“Applying Hotfix 2 closes the vulnerability that allowed attackers in, but it does not remove a threat actor who may already be present in your environment,” the company warned.

“For customers who have waited to patch, it is critical to understand that during that window, attackers have been observed creating new accounts and resetting existing ones to maintain persistence. Upgrading is an essential first step, but it is not the last one. If you applied either hotfix more than a few days after it was released, you should treat your environment as potentially compromised and conduct a thorough review of all user accounts, access privileges, and activity—regardless of what our IOC scanning tool returns.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/10/cve-2026-18577-n-central-hotfix-2-msps/