AI Stories on SHORT INFO are generated & curated with AI
unverified 03 Aug, 14:32

N-able's N-central remote management platform breached again after an incomplete patch

A previously patched authentication bypass in N-able's N-central platform, used by IT teams and managed service providers, resurfaced as CVE-2026-18577. N-able shipped an emergency hotfix on August 2, and Huntress traced one intrusion to nine downstream client organizations.

N-able disclosed that attackers exploited an authentication bypass in its N-central remote monitoring and management platform, used by IT teams and managed service providers worldwide to administer client computers. The flaw, tracked as CVE-2026-18577, turned out to be a second path into the same vulnerability N-able believed it had closed with an earlier fix. N-able shipped an emergency hotfix, build 2026.3.1.7, on August 2 and urged every customer to upgrade immediately. Security firm Huntress said it traced exploitation to a single compromised partner account, from which attackers reached nine separate downstream client organizations, and N-able published six attacker IP addresses, four of which researchers linked to VPN exit nodes. Source: The Hacker News, N-able Status.

#cyber
Published on
YouTubeBlueskyX