Security Affairs
U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog|31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register|AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek|River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted|PNLD Confirms Data Breach Affecting UK Police and Justice Staff|Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys|Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing|CareCloud Breach Exposes Medical and Financial Data of 345,000|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108|Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION|CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks|Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens|U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog|31,000 Records Compromised in Breach of Liechtenstein Companies and Foundations Register|AI Runs the Hack: Chinese Actor Automates Cyberattacks With DeepSeek|River Bank obtained assurances from the attackers that the stolen data in the June attack was deleted|PNLD Confirms Data Breach Affecting UK Police and Justice Staff|Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys|Ruby on Rails Patches Critical Active Storage Vulnerability Affecting Image Processing|CareCloud Breach Exposes Medical and Financial Data of 345,000|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108|Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION|CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks|Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an […]

CISA Minnesota Attacks

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a N-able N-central flaw, tracked as CVE-2026-18577 (CVSS score of 8.2), to its Known Exploited Vulnerabilities (KEV) catalog.

CVE-2026-18577 (CVSS 8.2) is an authentication bypass flaw caused by an incomplete fix for a previous vulnerability tracked as CVE-2026-18556. It allows remote attackers to take over accounts and gain administrative access to vulnerable N-able N-central servers. From there, they can use the built-in Take Control feature to move into managed endpoints and establish persistent access.

The company confirmed that a limited number of customers have been identified to be impacted by this, and, for those impacted customers, N‑able support has directly engaged. If you’re a customer who is not running the most recent version of N‑central, we strongly encourage you to upgrade to 2026.3.1.7.

Organizations can check for compromise by looking for a suspicious svchost.exe file in users’ Documents folders, a registered Cloudflared service, or inbound firewall connections from the listed IP addresses:

  • 173[.]249[.]252[.]200
  • 87[.]249[.]138[.]34
  • 37[.]19[.]210[.]32
  • 68[.]235[.]46[.]214. 

If any indicators are found, they should immediately contact N-able support and their security team.

Huntress researchers observed attackers exploiting CVE-2026-18577 against multiple organizations, although the activity does not yet appear to be widespread. After gaining access, attackers conducted reconnaissance, targeted domain controllers, enumerated processes, and moved laterally across networks.

“As Huntress continues our investigation and analysis of activity targeting vulnerable N-able N-central environments, we discovered that the four IPs N-able initially flagged as malicious are actually Mullvad or NordVPN VPN exit nodes.” reads the Huntress’s report. “Notably, among the original IPs, we have seen substantial traffic with 87.249.138[.]34 directly attributed to NordVPN, as well as substantial traffic with 37.19.210[.]32 directly attributed to Mullvad VPN. 37.19.210[.]32 has been previously abused for bruteforcing, spam, and other nefarious activity prior to this incident.”

N-able confirmed that a limited number of customers were compromised, highlighting the ongoing abuse of remote monitoring and management (RMM) platforms to gain persistent access.

Huntress warned that more than half (55.6%) of the reachable N-central cloud servers used by its partners and customers remained unpatched against CVE-2026-18577, leaving them exposed to exploitation. The company also noted that N-able added two more malicious IP addresses to its indicators of compromise and said it will continue investigating the attacks and provide updates as new findings emerge.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerability by the end of this week, on August 6, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)