CVE-2026-18556Active Exploitation(n-able / n-central)

CRITICALCVSS 7.4 · HIGHCISA KEV

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch n-able n-central systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

8.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-288

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n-central

Threat summary

  • Active exploitation appears in 38 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 62 mentions across 16 observed days

What's happening

  • Active exploitation reported across 38 signals
  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 43 signals
  • Technical details provided in 46 signals
  • Disclosure: 6 classified signals
  • Peaked 12d ago at 14 mentions (2026-08-04); latest day: 1
  • 62 total mentions across 16 days

Affected systems

Vendors
Products
n-central

Deep dive

Activity timeline62 mentions / 16d
0471114Mentions · 2026-08-01: 1Mentions · 2026-08-02: 4Mentions · 2026-08-03: 6Mentions · 2026-08-04: 14Mentions · 2026-08-05: 12Mentions · 2026-08-06: 5Mentions · 2026-08-07: 3Mentions · 2026-08-08: 2Mentions · 2026-08-09: 1Mentions · 2026-08-10: 5Mentions · 2026-08-11: 3Mentions · 2026-08-12: 1Mentions · 2026-09-06: 2Mentions · 2026-09-07: 1Mentions · 2026-09-08: 1Mentions · 2026-09-10: 1PoC Mentioned / Linked · 2026-08-08: 1PoC Mentioned / Linked · 2026-09-10: 1Exploit Tool / Code · 2026-08-04: 1Exploit Tool / Code · 2026-08-05: 1Exploit Tool / Code · 2026-08-08: 1Active Exploitation · 2026-08-02: 1Active Exploitation · 2026-08-03: 1Active Exploitation · 2026-08-04: 11Active Exploitation · 2026-08-05: 7Active Exploitation · 2026-08-06: 4Active Exploitation · 2026-08-07: 2Active Exploitation · 2026-08-08: 2Active Exploitation · 2026-08-09: 1Active Exploitation · 2026-08-10: 3Active Exploitation · 2026-08-11: 2Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-09-07: 1Active Exploitation · 2026-09-08: 1Active Exploitation · 2026-09-10: 1Patch / Workaround · 2026-08-02: 1Patch / Workaround · 2026-08-03: 5Patch / Workaround · 2026-08-04: 9Patch / Workaround · 2026-08-05: 6Patch / Workaround · 2026-08-06: 4Patch / Workaround · 2026-08-07: 2Patch / Workaround · 2026-08-08: 2Patch / Workaround · 2026-08-09: 1Patch / Workaround · 2026-08-10: 4Patch / Workaround · 2026-08-11: 3Patch / Workaround · 2026-08-12: 1Patch / Workaround · 2026-09-06: 2Patch / Workaround · 2026-09-07: 1Patch / Workaround · 2026-09-08: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-08-01: 1Technical Details · 2026-08-02: 1Technical Details · 2026-08-03: 5Technical Details · 2026-08-04: 10Technical Details · 2026-08-05: 8Technical Details · 2026-08-06: 4Technical Details · 2026-08-07: 2Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 1Technical Details · 2026-08-10: 4Technical Details · 2026-08-11: 3Technical Details · 2026-08-12: 1Technical Details · 2026-09-06: 2Technical Details · 2026-09-07: 1Technical Details · 2026-09-08: 1Technical Details · 2026-09-10: 108-0108-0208-0308-0408-0508-0608-0708-0808-0908-1008-1108-1209-0609-0709-0809-10
Signal classification4 categories
Active Exploitation
3150.0%
Patch
1930.6%
Disclosure
69.7%
General
69.7%
Referenced assets49 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-011
Disclosure1
2026-08-024
Active Exploitation1General3
2026-08-036
Active Exploitation1Disclosure2Patch3
2026-08-0414
Active Exploitation9Disclosure1Patch4
2026-08-0512
Active Exploitation6Disclosure1General2Patch3
2026-08-065
Active Exploitation4Patch1
2026-08-073
Active Exploitation2Patch1
2026-08-082
Active Exploitation1Patch1
2026-08-091
Active Exploitation1
2026-08-105
Active Exploitation3General1Patch1
2026-08-113
Active Exploitation2Patch1
2026-08-121
Active Exploitation1
2026-09-062
Disclosure1Patch1
2026-09-071
Patch1
2026-09-081
Patch1
2026-09-101
Patch1
Full discourse20 posts
  • CISA Cyber@CISACyber
    Active Exploitation

    🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/mWcFU47aU3

    Post summary

    Three CVEs are now listed in the DHS KEV catalog and the tweet urges organizations to apply mitigations, implying active exploitation.

    619143711.0K
    302.2K followersView on X
  • mRr3b00t@UK_Daniel_Card
    Active Exploitation

    Daniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026 Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today. 1. CISA KEV / actively exploited (lead) CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised. CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today. CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target. CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today. CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks. 2. Edge / network gear CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate. Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched. 3. Microsoft / Windows / AD Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap. 4. Web / cloud / DevOps CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1. CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep. Watch / developing Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks. Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes. Sources: CISA — Adds Three KEVs (Aug 4) CISA — Adds One KEV (Aug 3) The Hacker News — CISA flags Langflow, Tomcat, N-central Rapid7 — CVE-2026-18577 N-central exploited in the wild N-able — N-central Security Update (Aug 2) The Hacker News — Cisco FMC zero-day actively exploited BleepingComputer — Rails Active Storage RCE (CVE-2026-66066) BleepingComputer — WordPress wp2shell RCE public exploits SecurityWeek — Fortinet/Ivanti critical patches Senserva — CISA KEV additions this week One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.

    Post summary

    The briefing details several CVEs—primarily CVE-2026-18577—that are actively exploited in the wild, provides mitigation patches, and highlights urgent patching deadlines.

    22015512.4K
    125.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(08/04追加) #vulnerability 🛡CVE-2026-9198 IBM Langflow Code Injection Vulnerability ✅概要 ・深刻度:緊急 9.8 (CVSS Base) / IBM Corporation (CNA) ・種別:コード・インジェクション (CWE-94) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H IBM Langflow OSS 1.0.0 から 1.10.0 に存在するコードインジェクションの脆弱性です。 未認証の攻撃者が /api/v1/auto_login で SUPERUSER トークンを取得し、/api/v1/validate/code で任意コードを実行することで、既定構成の Langflow 環境でリモートコード実行に至る可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・IBM Langflow OSS 1.0.0 から 1.10.0 を使用している ・/api/v1/auto_login がネットワーク経由で到達可能である ・/api/v1/validate/code がネットワーク経由で到達可能である ・既定構成で auto-login 機能が有効である ・Langflow OSS 1.10.1 以降へ更新されていない ✅悪用時影響 ・未認証の攻撃者に SUPERUSER トークンを取得される可能性がある ・Langflow のコード検証機能を悪用される可能性がある ・対象ホスト上で任意の Python コードを実行される可能性がある ・APIキー、環境変数、外部連携先の認証情報を窃取される可能性がある ・Langflow 環境を起点に追加侵害へつなげられる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:未確認 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-9198 ・https://www.ibm.com/support/pages/node/7278927 ・https://github.com/cisagov/vulnrichment/blob/develop/2026/9xxx/CVE-2026-9198.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-9198 ・https://jvndb.jvn.jp/ja/cwe/CWE-94.html 🛡CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / N-able (CNA) ・種別:代替パスまたはチャネルを使用した認証回避 (CWE-288) ・CVSS:CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N N-able N-central に存在する、代替パスまたはチャネルを使用した認証回避の脆弱性です。 N-central 2026.1 までのバージョンが影響を受け、認証バイパスにつながる可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:完全制御 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・N-able N-central 2026.1 以前を使用している ・攻撃者が N-central サーバーへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・N-central 2026.3.1.7 以降へ更新されていない ・関連する修正済みホットフィックスが適用されていない ✅悪用時影響 ・認証をバイパスされる可能性がある ・N-central サーバーへの管理アクセス取得につながる可能性がある ・管理対象エンドポイントへ到達される可能性がある ・Take Control 機能などを悪用される可能性がある ・Cloudflare Tunnel などを用いた永続化に悪用される可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(N-able) ・概要:N-able は、2026年7月31日に Adlumin MDR が顧客環境で不審な活動を検知し、N-central サーバーのゼロデイ悪用を確認したと公表。 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-18556 ・https://www.n-able.com/blog/n-central-security-update-august-4-2026 ・https://uptime.n-able.com/ ・https://github.com/cisagov/vulnrichment/blob/develop/2026/18xxx/CVE-2026-18556.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556 ・https://jvndb.jvn.jp/ja/cwe/CWE-288.html 🛡CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability ✅概要 ・深刻度:重要 7.5 (CVSS Base) / CISA-ADP ・種別:重要なデータの暗号化の欠如 (CWE-311) ・CVSS:CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Apache Tomcat の EncryptInterceptor に存在する、重要なデータの暗号化の欠如に関する脆弱性です。 CVE-2026-29146 の修正に起因して EncryptInterceptor のバイパスが可能となり、機密データが暗号化されない可能性があります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:高 ・悪用難易度:低 ✅CISA 評価 ・攻撃自動化:自動化は可能 ・技術的影響:部分的 ・BOD 26-04 対処期限(露出あり):2026年8月7日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・Apache Tomcat 11.0.20、10.1.53、または 9.0.116 を使用している ・Tomcat クラスタリング等で EncryptInterceptor を使用している ・攻撃者が EncryptInterceptor により保護される通信経路へ影響を及ぼせる ・Apache Tomcat 11.0.21、10.1.54、または 9.0.117 以降へ更新されていない ・CVE-2026-29146 の修正を含む影響バージョンを利用している ✅悪用時影響 ・EncryptInterceptor による暗号化をバイパスされる可能性がある ・本来暗号化されるべきデータが平文で扱われる可能性がある ・Tomcat クラスタ間通信などで機密データが漏えいする可能性がある ・機密性に高い影響が生じる可能性がある ✅悪用事例等に関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(SOCRadar) ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-34486 ・https://tomcat.apache.org/security-11.html ・https://tomcat.apache.org/security-10.html ・https://tomcat.apache.org/security-9.html ・https://lists.apache.org/thread/9510k5p5zdvt9pkkgtyp85mvwxo2qrly ・https://github.com/cisagov/vulnrichment/blob/develop/2026/34xxx/CVE-2026-34486.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-34486 ・https://socradar.io/blog/snowlight-government-chinese-campaign/ ・https://jvndb.jvn.jp/ja/cwe/CWE-311.html ・https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog #vulnerability

    Post summary

    CISA has cataloged three CVEs including IBM Langflow injection, N‑able N‑central authentication bypass, and Apache Tomcat encryption omission—one of which (CVE‑2026‑18556) has confirmed zero‑day exploitation and all are accompanied by vendor advisories and detailed technical data.

    010935.3K
    44.3K followersView on X
  • piyokango@piyokango
    Active Exploitation

    米国CISAが悪用を確認した脆弱性 #KEV をカタログに追加しました。(8/3追加) CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability ✅概要 ・深刻度:重要 8.2 (CVSS Base) / N-able (CNA) ・種別:代替パスまたはチャネルを使用した認証回避 (CWE-288) ・CVSS:CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A N-able N-central に存在する、代替パスまたはチャネルを使用した認証回避の脆弱性です。 CVE-2026-18556 に対する修正が不完全であったことにより、N-central 2026.3.1 までのバージョンで認証バイパスおよびアカウント乗っ取りが可能となります。 ✅ChatGPTによる脆弱性評価 ・国内影響度:中 ・悪用難易度:中 ✅CISA 評価 ・攻撃自動化:自動化は困難 ・技術的影響:部分的 ・BOD 26-04 対処期限(露出あり):2026年8月6日 ・BOD 26-04 対処期限(露出なし):2026年8月18日 ✅攻撃前提条件 ・N-able N-central を使用している ・N-central 2026.3.1 以前の影響を受けるバージョンを使用している ・攻撃者が N-central サーバーへネットワーク経由でアクセスできる ・攻撃者は認証情報を必要としない ・N-central 2026.3.1.7 以降へ更新されていない ✅悪用時影響 ・認証をバイパスされる可能性がある ・N-central 上のアカウントを乗っ取られる可能性がある ・N-central サーバーに対するリモート管理アクセスを取得される可能性がある ・管理対象エンドポイントへ Take Control 機能などを通じて到達される可能性がある ・Cloudflare Tunnel などを用いた永続化に悪用される可能性がある ✅悪用事例等に 関する公開情報 ・PoC/Exploit:公開情報確認できず ・ITW:確認済み(N-able / Huntress) ・概要:Huntress は自己ホスト型 N-central インスタンスに対する悪用を確認し、複数組織配下のエンドポイントへ到達された事例を報告 ✅関連情報 ・https://nvd.nist.gov/vuln/detail/CVE-2026-18577 ・https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm ・https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ ・https://github.com/cisagov/vulnrichment/blob/develop/2026/18xxx/CVE-2026-18577.json ・https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577 ・https://www.huntress.com/blog/critical-n-able-n-central-vulnerability-actively-exploited ・https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html ・https://jvndb.jvn.jp/ja/cwe/CWE-288.html #vulnerability

    Post summary

    CVE-2026-18577 is a high‑severity authentication bypass in N‑able N‑central, actively exploited in the wild as confirmed by CISA and Huntress, yet no public exploit code exists.

    0101115.3K
    44.3K followersView on X
  • Ryan Dewhurst@ethicalhack3r
    Disclosure

    This morning N-able have released a second CVE (CVE-2026-18577) Due to an incomplete patch in the first (CVE-2026-18556) Unauth admin account takeover

    Post summary

    N‑Able released CVE‑2026‑18577, a second vulnerability linked to an incomplete patch on the first CVE, exposing potential unauthenticated admin account takeover.

    040611.6K
    21.2K followersView on X
  • KEVIntel@kev_intel
    Active Exploitation

    🚨 N-able N-central is being actively exploited via CVE-2026-18556. On-premises deployments running 2026.1 or earlier should upgrade to 2026.3 immediately. We’ve not yet observed exploitation in KEVIntel sensors, but we’re actively monitoring.

    Post summary

    N‑able N‑central is actively exploited via CVE‑2026‑18556; users should immediately upgrade to version 2026.3.

    121613.0K
    61 followersView on X
  • キタきつね@foxbook
    Active Exploitation

    CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4) CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性 CVE-2026-18556 N-able N-central認証バイパス(代替パスまたはチャネルの使用)の脆弱性 CVE-2026-34486 Apache Tomcatにおける機密データの暗号化の欠落の脆弱性 https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog

    Post summary

    CISA reports that three CVEs—IBM Langflow code injection, N‑able N‑central authentication bypass, and Apache Tomcat encryption omission—are being actively exploited, with no patch or PoC details provided.

    01023316
    5.0K followersView on X
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik #GüvenlikBülteni Merhaba #Brolyz 🎯 Zafiyet Bilgisi Ürün: N-able N-central Zafiyet: Kimlik Doğrulama Atlatma (Authentication Bypass) CVE: CVE-2026-18556 Zafiyet Türü: Alternatif Yol veya Kanal Kullanarak Kimlik Doğrulama Atlatma (CWE-288) Fidye Yazılımı İlişkisi: Şu an için bilinmiyor. 📌 Zafiyet Özeti N-able N-central üzerinde Kimlik Doğrulama Atlatma (Authentication Bypass) zafiyeti tespit edilmiştir. Bu güvenlik açığı, saldırganların standart kimlik doğrulama mekanizmalarını atlayarak sisteme yetkisiz erişim sağlamasına olanak tanıyabilir. Başarılı bir istismar sonucunda saldırgan; yönetim yetkileri elde edebilir, istemci sistemlerini yönetebilir, güvenlik yapılandırmalarını değiştirebilir, kurumsal ağ içerisinde yatay hareket gerçekleştirebilir ve kritik altyapıyı riske atabilir. 🛡️ Önerilen Aksiyonlar ✅ Güvenlik Güncellemeleri N-able tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın. N-central sunucularını desteklenen en güncel sürüme yükseltin. ✅ Risk Yönetimi Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin. ✅ Erişim Kontrolleri İnternete açık N-central sunucularını öncelikli olarak değerlendirin. Yönetim arayüzünü yalnızca güvenilir ağlardan erişilebilir hale getirin. Çok faktörlü kimlik doğrulama (MFA), IP kısıtlamaları ve erişim günlüklerini düzenli olarak izleyin. ✅ Geçici Koruma Önlemleri Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, N-central sunucusunun internet erişimini sınırlandırın veya yalnızca VPN üzerinden erişilebilir hale getirin. Gerekirse yönetim arayüzünü geçici olarak devre dışı bırakmayı değerlendirin. 📚 Referans: N-able Security Advisory & CISA

    Post summary

    The bulletin announces CVE‑2026‑18556 (authentication bypass in N‑able N‑central) and focuses on recommending vendor patches, mitigations, and temporary protective steps.

    0104057
    523 followersView on X
  • YourDailyCVE@YourDailyCVE
    Patch

    🚨 CVE-2026-86218 — N-able N-central, pre-auth RCE. CVSS 10.0. What broke: this is the remote-control tower for customer PCs. The new bug lets someone with no password run code on that tower. Own N-central and you can push scripts, open remote sessions, and touch every endpoint it manages. Who should care: MSPs and enterprise IT running N-central — every build before 2026.3.1.14. That includes servers you just put on Hotfix 3 yesterday. Hosted N-central (NCOD) is already patched by N-able. On-prem is on you. Shadowserver still sees about 1,500 consoles on the internet. Why that matters: August’s N-central bugs (CVE-2026-18556 / 18577) were already used to walk from the console into customer networks and leave tunnels behind. This is the third serious wave in about six weeks. Status: N-able’s public notes say no confirmed production hits. A separate customer/incident notice called it a zero-day “observed being exploited in the wild.” Huntress flagged it as a possible zero-day too. Not on CISA KEV yet. Responsible disclosure; no public how-to from the vendor. Fix today: N-central 2026.3 Hotfix 4 — build 2026.3.1.14. Direct path from 2025.4, 2026.1, 2026.2, 2026.3, and HF1–HF3. Agents do not need an upgrade for this CVE. Can't patch: take the N-central console off the public internet. Restrict it to VPN / allowlisted admin IPs. Audit admin accounts for new or odd users (Huntress also patched an auth-bypass pair over the weekend: CVE-2026-86206 / 86207). Do this now: check the build. If it is not 2026.3.1.14, install HF4 today and reply “patched.”Source: N-able status / http://CVE.org / Help Net Security / BleepingComputer #Nable #RMM

    Post summary

    N‑central within the 2026.3 line has a pre‑auth RCE (CVE‑2026‑86218) with CVSS 10.0; a hotfix is available and some reports indicate possible exploitation in the wild.

    20020280
    29 followersView on X
  • Lupovis@LupovisDefence
    Patch

    @Nable published an N-central security advisory for CVE-2026-18556 and CVE-2026-18577 on Aug 2 with 6 IOC IP addresses. We were already tracking 2 of them two months before disclosure. CVE-2026-18577 was announced after an incomplete patch for CVE-2026-18556 was released. The exploit grants administrator access on N-central (through 2026.3.1). It's being exploited in the wild right now. We cross-referenced N-able's 6 published indicators against Lupovis deception telemetry. Two matched: • 37.19.210.32 (Datacamp): 27 recon events against our sensors • 68.235.46.214 (tzulo): reconnaissance plus credential brute-forcing Our earliest sighting: May 27. Roughly two months before the advisory. The IPs in the bulletin were known for probing, enumerating and password-spraying long before anyone published a CVE number. That's the point of Lupovis. The IOC list is the end of the story. The traffic is the start of it. If you run N-central on-prem: → Upgrade to 2026.3.1.7 today → Block all 6 advisory IOC IPs → Hunt for rogue services and unexpected Cloudflare tunnels (the documented persistence method) No public PoC exists yet. Active exploitation isn't waiting for one. N-able's advisory (indicators and guidance): https://www.n-able.com/blog/n-central-security-update-august-2-2026 Want to block threat actors before a 0-day drops? Try our insights[dot]lupovis[dot].io platform #ThreatIntel #CVE #Ncentral #KEV #DeceptionTechnology #MSP

    Post summary

    N‑able issued an advisory for CVE‑2026‑18556/77 with IOC; exploitation is active, and the primary mitigation is upgrading to 2026.3.1.7 and blocking listed IPs.

    00102234
    576 followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX
    Disclosure

    🚨 CRITICAL RCE — N-ABLE HAS RELEASED AN EMERGENCY N-CENTRAL HOTFIX FOR A NEW CVSS 10 PRE-AUTHENTICATION REMOTE CODE EXECUTION FLAW No credentials. No user interaction. Network-accessible exploitation. CyberSignal Priority: 🔴 VERY HIGH CVE: CVE-2026-86218 Product: N-able N-central CVSS v4.0: 10.0 CRITICAL Affected: versions before 2026.3.1.14 Fixed: 2026.3 HF4 / build 2026.3.1.14 Disclosure: September 6, 2026 ### 🔎 What happened N-able disclosed a new critical vulnerability in N-central today. CVE-2026-86218 allows PRE-AUTHENTICATION REMOTE CODE EXECUTION against vulnerable N-central servers. The CVSS vector is especially serious: Network reachable + Low attack complexity + No privileges required + No user interaction + High confidentiality, integrity and availability impact. N-able classifies the weakness as CWE-96 — improper neutralization of directives in statically saved code. Technical details about the vulnerable endpoint or exact exploitation mechanism have not yet been publicly disclosed. ### 🎯 What is affected N-central: < 2026.3.1.14 On-premises administrators should move to: 2026.3 HF4 build 2026.3.1.14 N-able says hosted N-central environments have already received the mitigation. Even organizations that installed HF3 need HF4 for this newly disclosed issue. ### ⚠️ Exploitation status — important distinction There is conflicting public information. An N-able representative said a third independent researcher reported a NEW vulnerability that had been: “exploited in the wild.” However, currently indexed CVE and vulnerability-tracking data do not independently confirm an exploitation campaign, and no public PoC or exploit module has been identified at this time. Therefore: VENDOR REPRESENTATIVE CLAIM: Exploitation in the wild reported. INDEPENDENT CONFIRMATION: Not established yet. CISA KEV: Not listed at the time of this post. Public PoC: None identified. Do NOT confuse CVE-2026-86218 with the earlier N-central vulnerabilities CVE-2026-18556, CVE-2026-18577, CVE-2026-86206 or CVE-2026-86207. ### 🛡️ Defender action ON-PREMISES N-CENTRAL: → Upgrade to 2026.3 HF4 immediately → Confirm the actual server build is 2026.3.1.14 or later → Restrict N-central exposure to trusted administrative networks/IPs → Review recent server activity and administrative changes → Treat unexpected N-central server behavior as potentially high-impact ### 🧠 Why this matters N-central is not an ordinary application. It is a remote monitoring and management platform used to administer other systems. That creates an asymmetric blast radius: ONE MANAGEMENT SERVER ↓ MANY MANAGED ENDPOINTS ↓ MULTIPLE CUSTOMER ENVIRONMENTS. A compromise of the control plane can therefore be considerably more damaging than compromise of a normal standalone server. ### 🧠 CyberSignal Insight The CVSS 10 is only part of the story. The more important security property is TRUST CONCENTRATION. An attacker who compromises software designed to remotely administer fleets of machines may inherit the same authority defenders intentionally gave that platform. That is why pre-auth RCE in an RMM management plane deserves emergency treatment even before the full exploitation picture is known. Sources: N-able · NVD/CVE · Huntress · public N-able representative communication

    Post summary

    The post announces a critical pre‑authentication RCE flaw (CVE‑2026‑86218) in N‑able N‑central, details an emergency hotfix and patch procedure, notes unverified claims of wild exploitation, and urges immediate remediation steps.

    01010158
    202 followersView on X
  • CyberSignal | Cybersecurity & AI News@XQOPTRX
    Patch

    🚨 CRITICAL RCE — N-ABLE HAS RELEASED AN EMERGENCY N-CENTRAL HOTFIX FOR A NEW CVSS 10 PRE-AUTHENTICATION REMOTE CODE EXECUTION FLAW No credentials. No user interaction. Network-accessible exploitation. CyberSignal Priority: 🔴 VERY HIGH CVE: CVE-2026-86218 Product: N-able N-central CVSS v4.0: 10.0 CRITICAL Affected: versions before 2026.3.1.14 Fixed: 2026.3 HF4 / build 2026.3.1.14 Disclosure: September 6, 2026 🔎 What happened N-able disclosed a new critical vulnerability in N-central today. CVE-2026-86218 allows PRE-AUTHENTICATION REMOTE CODE EXECUTION against vulnerable N-central servers. The CVSS vector is especially serious: Network reachable + Low attack complexity + No privileges required + No user interaction + High confidentiality, integrity and availability impact. N-able classifies the weakness as CWE-96 — improper neutralization of directives in statically saved code. Technical details about the vulnerable endpoint or exact exploitation mechanism have not yet been publicly disclosed. 🎯 What is affected N-central: < 2026.3.1.14 On-premises administrators should move to: 2026.3 HF4 build 2026.3.1.14 N-able says hosted N-central environments have already received the mitigation. Even organizations that installed HF3 need HF4 for this newly disclosed issue. ⚠️ Exploitation status — important distinction There is conflicting public information. An N-able representative said a third independent researcher reported a NEW vulnerability that had been: “exploited in the wild.” However, currently indexed CVE and vulnerability-tracking data do not independently confirm an exploitation campaign, and no public PoC or exploit module has been identified at this time. Therefore: VENDOR REPRESENTATIVE CLAIM: Exploitation in the wild reported. INDEPENDENT CONFIRMATION: Not established yet. CISA KEV: Not listed at the time of this post. Public PoC: None identified. Do NOT confuse CVE-2026-86218 with the earlier N-central vulnerabilities CVE-2026-18556, CVE-2026-18577, CVE-2026-86206 or CVE-2026-86207. 🛡️ Defender action ON-PREMISES N-CENTRAL: → Upgrade to 2026.3 HF4 immediately → Confirm the actual server build is 2026.3.1.14 or later → Restrict N-central exposure to trusted administrative networks/IPs → Review recent server activity and administrative changes → Treat unexpected N-central server behavior as potentially high-impact 🧠 Why this matters N-central is not an ordinary application. It is a remote monitoring and management platform used to administer other systems. That creates an asymmetric blast radius: ONE MANAGEMENT SERVER ↓ MANY MANAGED ENDPOINTS ↓ MULTIPLE CUSTOMER ENVIRONMENTS. A compromise of the control plane can therefore be considerably more damaging than compromise of a normal standalone server. 🧠 CyberSignal Insight The CVSS 10 is only part of the story. The more important security property is TRUST CONCENTRATION. An attacker who compromises software designed to remotely administer fleets of machines may inherit the same authority defenders intentionally gave that platform. That is why pre-auth RCE in an RMM management plane deserves emergency treatment even before the full exploitation picture is known. Sources: N-able · NVD/CVE · Huntress · public N-able representative communication

    Post summary

    N‑Able issued an emergency hot‑fix for CVE‑2026‑86218, a critical pre‑auth RCE vulnerability; no public PoC or exploit exists and active exploitation has not been confirmed.

    01010139
    202 followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Active Exploitation

    🚨Upozorňujeme na aktivně zneužívanou zranitelnost v nástroji pro vzdálenou správu N-able N-central, CVE-2026-18577. Zranitelnost vznikla v důsledku neúplné opravy zranitelnosti CVE-2026-18556 a umožňuje vzdálenému neautentizovanému útočníkovi obejít ověřování a získat administrátorskou kontrolu nad zasaženým serverem N-central. Vzhledem k tomu, že platforma slouží pro vzdálenou správu koncových zařízení, může úspěšné zneužití vést k převzetí spravovaných systémů, zneužití funkce Take Control pro vzdálený přístup, vytvoření perzistence prostřednictvím nástroje Cloudflare Tunnel (cloudflared) a dalšímu šíření kompromitace v prostředí organizace. Zranitelnost je podle výrobce aktivně zneužívána od 1. srpna 2026 a byla zařazena do katalogu známých zneužívaných zranitelností CISA KEV. Postiženy jsou verze N-able N-central starší než 2026.3.1.7. Mezi indikátory kompromitace patří přítomnost služby cloudflared, podezřelý soubor svchost.exe umístěný ve složce Documents uživatele, vytvoření nebo úpravy administrátorských účtů, neobvyklá aktivita funkcionality Take Control, instalace nových služeb Windows a komunikace s IP adresami 173.249.252[.]176, 173.249.252[.]200, 185.156.46[.]150, 23.234.94[.]43, 37.153.90[.]88, 37.19.210[.]32, 68.235.46[.]214, 68.235.46[.]235, 87.249.138[.]34 a 92.118.112[.]181. 📌Doporučujeme aktualizovat na verzi 2026.3.1.10 (Hotfix 2), prověřit systémy na přítomnost indikátorů kompromitace a zkontrolovat autentizační logy, změny administrátorských účtů, aktivitu Take Control a komunikaci s publikovanými IoC adresami.

    Post summary

    The post alerts that CVE‑2026‑18577 is actively exploited in the wild, lists indicators of compromise, and recommends a specific patch, underscoring an ongoing attack campaign.

    01010543
    4.3K followersView on X
  • ThreatLocker@ThreatLocker
    Patch

    The ThreatLocker Threat Intelligence Team analyzed the advisory released by N-able for CVE-2026-18556, affecting version 2026.1 of their RMM platform, N-central. CVE-2026-18556 is an authentication bypass flaw in N-central that affects both on-premises and cloud deployments. Attackers could gain administrative access, execute scripts, automate jobs, modify configurations, and potentially impact downstream customers. Although exploitation details have not been released, the disclosed impact is severe. Mitigation steps to follow: -Patch all N-central servers to 2026.3.1.7 immediately -Take unpatched servers offline -Restrict public N-central console access -Review admin accounts and permissions -Revoke suspicious account access -Audit logs for remote access, scripts, and jobs -Hunt for Cloudflared and svchost.exe -Check network logs against listed IOCs To read the full breakdown: https://www.threatlocker.com/blog/n-able-n-central-vulnerability-grants-unauthenticated-users-god-mode

    Post summary

    The post alerts on a severe authentication bypass in N‑central, provides a patch (version 2026.3.1.7) and mitigation steps, but offers no exploitation details or PoC.

    00020211
    2.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-86218, a critical pre-auth RCE in N-able N-central, is patched in build 2026.3.1.14 (HF4). Two earlier flaws, CVE-2026-18556 and CVE-2026-18577, are in CISA KEV as actively exploited. #DFIR_Radar https://t.co/dPAXzompjp

    Post summary

    The message announces that CVE-2026-86218, a critical pre-auth RCE in N-able N-central, has been patched in build 2026.3.1.14 (HF4), and notes that two earlier CVEs are listed in the CISA KEV as actively exploited.

    10000205
    1.9K followersView on X
  • iototsecnews@iototsecnews
    Active Exploitation

    N-able の脆弱性 CVE-2026-18577/18556 が FIX:実環境での悪用を確認 https://iototsecnews.jp/2026/08/03/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/ この記事は、N-able N-central において報告されたセキュリティ情報を紹介するものです。この問題の原因は、過去の修正における不備により認証を迂回するパスが残存していた点にあります。悪用された場合、管理権限が乗っ取られ、管理対象となるネットワークや接続機器へ向けて被害が拡大する恐れがあります。特定された脆弱性は CVE-2026-18577/CVE-2026-18556 です。対応策として、開発元が配信する修正プログラムの適用が有効です。システムを安全に利用するためにも、不審な通信や端末内の不審プログラムの有無を確認し、更新プログラムを速やかに適用することが推奨されます。 #CVE202618556 #CVE202618577 #Exploit #Nable #NCentral #Vulnerability

    Post summary

    The CVEs 2026‑18577/18556 in N‑able N‑central have been confirmed as exploited in the wild, enabling authentication bypass and potential administrative takeover. A patch has been released; users should install it immediately and monitor for suspicious activity.

    01000161
    507 followersView on X
  • CVE Brief@DailyCVEBrief
    Active Exploitation

    DEEP DIVE — CVE-2026-18556: unauthenticated auth bypass in N-able N-central, KEV-listed and exploited in the wild. Patched to 2026.2 back in April? Still exploitable, the fix was incomplete. Only build 2026.3.1.10 is current. https://t.co/Kq3nyV0OZN

    Post summary

    CVE-2026-18556, an unauthenticated authentication bypass in N‑able N‑central, is KEV‑listed and actively exploited; current vendor patches reach only build 2026.3.1.10, leaving earlier versions vulnerable.

    1000059
    26 followersView on X
  • CyberTLDR@CyberTLDR
    Active Exploitation

    2/3 CVE-2026-18577 (CVSS 8.2) hits every N-central version before 2026.3.1.7. It was found under exploitation on July 31 and is an incomplete fix for CVE-2026-18556, so the first patch left a gap attackers kept using to persist. #InfoSec #CVE #CyberAttack

    Post summary

    CVE‑2026‑18577 remains exploitable in N‑central versions older than 2026.3.1.7; an incomplete patch created a maintenance window that attackers exploited, and the vulnerability is actively used in the wild.

    1000066
    41 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-18556 and CVE-2026-18577 (CVSS 8.2) in N-able N-central are actively exploited, giving attackers unauthenticated admin access to RMM servers and every downstream managed endpoint. - Two auth bypass flaws let an unauthenticated remote attacker gain full administrative control of N-central. N-able confirmed active exploitation on Aug 1, 2026. The first clean build is 2026.3.1.7; upgrading only to 2026.3 is NOT sufficient, as CVE-2026-18577 persisted through 2026.3.1. - Attackers abused N-central's built-in Take Control feature to reach managed endpoints, then registered a Cloudflare tunnel service for persistent access. Persistence lives on the downstream endpoint, not the RMM server, so patching N-central alone does not evict an attacker already inside. - Hunt for unexpected cloudflared services or svchost.exe running from a user's Documents folder. Review N-central ui_access_control.log and endpoint logs at C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz for unaccountable Take Control sessions, especially tied to apparent N-able support identities. - Published IOCs include IPs 173.249.252[.]200, 87.249.138[.]34, 37.19.210[.]32, 37.153.90[.]88, 92.118.112[.]181, 68.235.46[.]214 and domains mousears.synology[.]me and http://wagoosh.direct.quickconnect[.]to. Huntress notes the first four IPs are Mullvad/NordVPN exit nodes, so treat blocking as partial only. #DFIR_Radar

    Post summary

    The N‑able N‑central vulnerabilities CVE‑2026‑18556 and CVE‑2026‑18577 are actively exploited in the wild, allowing unauthenticated admin access and persistence via Take Control with a Cloudflare tunnel. Patch to build 2026.3.1.7 is required, and monitoring for specific IOCs is recommended.

    10000164
    1.8K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ BOLLETTINO CYBER | 06/08/2026 1. Vulnerabilità critica in JetBrains TeamCity in sfruttamento attivo CSIRT Italia e CISA segnalano la CVE-2026-63077 (CVSS 9.8): RCE non autenticata su tutte le versioni on-premise di TeamCity tramite il protocollo agent polling. Aggiornare subito alle versioni 2025.11.7 o 2026.1.3 (o applicare il plugin di sicurezza). 2. ChainDrop: worm auto-propagante colpisce oltre 400 pacchetti npm Campagna supply-chain identificata da CSIRT Italia che compromette pacchetti ampiamente usati (keyv, flat-cache e altri) con oltre 2 miliardi di download mensili. Il malware ruba credenziali e si propaga automaticamente. Controllare immediatamente le dipendenze e i lockfile. 3. CISA: vulnerabilità sfruttate in Langflow, N-central e Apache Tomcat Tre flaw aggiunti al KEV catalog (CVE-2026-9198, CVE-2026-18556/18577 e CVE-2026-34486). Consentono RCE, bypass di autenticazione e altre compromissioni. Le agenzie federali USA hanno solo pochi giorni per mettere in sicurezza i sistemi. 4. Creatore di Ransom Cartel condannato a 16 anni di carcere Maksim Silnikau, fondatore del ransomware-as-a-service attivo dal 2021, è stato condannato negli USA. L’operazione ha colpito almeno 18 aziende in più paesi. Un segnale importante nella lotta al RaaS. Priorità assoluta: patchare TeamCity e verificare le supply chain npm. #Cybersecurity #CyberItalia

    Post summary

    JetBrains TeamCity suffers an actively exploited RCE (CVE‑2026‑63077) and the advisory urgently recommends applying the latest patches; the text highlights active exploitation and patch‑remediation.

    10000121
    51 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn-ablen-central---

Explore more