Exploitation observed; activity peaked at 14 mentions and remains active
Immediate actions
Patch n-able n-central systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-07. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/mWcFU47aU3
Post summary
Three CVEs are now listed in the DHS KEV catalog and the tweet urges organizations to apply mitigations, implying active exploitation.
Daniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026
Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today.
1. CISA KEV / actively exploited (lead)
CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised.
CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today.
CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target.
CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today.
CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks.
2. Edge / network gear
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate.
Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched.
3. Microsoft / Windows / AD
Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap.
4. Web / cloud / DevOps
CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1.
CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep.
Watch / developing
Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks.
Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes.
Sources:
CISA — Adds Three KEVs (Aug 4)
CISA — Adds One KEV (Aug 3)
The Hacker News — CISA flags Langflow, Tomcat, N-central
Rapid7 — CVE-2026-18577 N-central exploited in the wild
N-able — N-central Security Update (Aug 2)
The Hacker News — Cisco FMC zero-day actively exploited
BleepingComputer — Rails Active Storage RCE (CVE-2026-66066)
BleepingComputer — WordPress wp2shell RCE public exploits
SecurityWeek — Fortinet/Ivanti critical patches
Senserva — CISA KEV additions this week
One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.
Post summary
The briefing details several CVEs—primarily CVE-2026-18577—that are actively exploited in the wild, provides mitigation patches, and highlights urgent patching deadlines.
CISA has cataloged three CVEs including IBM Langflow injection, N‑able N‑central authentication bypass, and Apache Tomcat encryption omission—one of which (CVE‑2026‑18556) has confirmed zero‑day exploitation and all are accompanied by vendor advisories and detailed technical data.
CVE-2026-18577 is a high‑severity authentication bypass in N‑able N‑central, actively exploited in the wild as confirmed by CISA and Huntress, yet no public exploit code exists.
This morning N-able have released a second CVE (CVE-2026-18577)
Due to an incomplete patch in the first (CVE-2026-18556)
Unauth admin account takeover
Post summary
N‑Able released CVE‑2026‑18577, a second vulnerability linked to an incomplete patch on the first CVE, exposing potential unauthenticated admin account takeover.
🚨 N-able N-central is being actively exploited via CVE-2026-18556.
On-premises deployments running 2026.1 or earlier should upgrade to 2026.3 immediately.
We’ve not yet observed exploitation in KEVIntel sensors, but we’re actively monitoring.
Post summary
N‑able N‑central is actively exploited via CVE‑2026‑18556; users should immediately upgrade to version 2026.3.
CISAが既知の悪用された脆弱性3件をカタログに追加
CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4)
CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性
CVE-2026-18556 N-able N-central認証バイパス(代替パスまたはチャネルの使用)の脆弱性
CVE-2026-34486 Apache Tomcatにおける機密データの暗号化の欠落の脆弱性
https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
Post summary
CISA reports that three CVEs—IBM Langflow code injection, N‑able N‑central authentication bypass, and Apache Tomcat encryption omission—are being actively exploited, with no patch or PoC details provided.
🪲🪲🪲 Siber Güvenlik Zaafiyet Bülteni #SiberGüvenlik#GüvenlikBülteni
Merhaba #Brolyz
🎯 Zafiyet Bilgisi
Ürün: N-able N-central
Zafiyet: Kimlik Doğrulama Atlatma (Authentication Bypass)
CVE: CVE-2026-18556
Zafiyet Türü: Alternatif Yol veya Kanal Kullanarak Kimlik Doğrulama Atlatma (CWE-288)
Fidye Yazılımı İlişkisi: Şu an için bilinmiyor.
📌 Zafiyet Özeti
N-able N-central üzerinde Kimlik Doğrulama Atlatma (Authentication Bypass) zafiyeti tespit edilmiştir.
Bu güvenlik açığı, saldırganların standart kimlik doğrulama mekanizmalarını atlayarak sisteme yetkisiz erişim sağlamasına olanak tanıyabilir.
Başarılı bir istismar sonucunda saldırgan; yönetim yetkileri elde edebilir, istemci sistemlerini yönetebilir, güvenlik yapılandırmalarını değiştirebilir, kurumsal ağ içerisinde yatay hareket gerçekleştirebilir ve kritik altyapıyı riske atabilir.
🛡️ Önerilen Aksiyonlar
✅ Güvenlik Güncellemeleri
N-able tarafından yayımlanan güvenlik güncellemelerini ve önerilen hafifletici önlemleri (Mitigations) test ettikten sonra en kısa sürede canlı ortama uygulayın.
N-central sunucularını desteklenen en güncel sürüme yükseltin.
✅ Risk Yönetimi
Süreçlerinizi CISA'nın BOD 26-04 (Risk Tabanlı Güvenlik Güncellemelerinin Önceliklendirilmesi) ve Forensics Triage Requirements rehberlerine uygun şekilde yönetin.
✅ Erişim Kontrolleri
İnternete açık N-central sunucularını öncelikli olarak değerlendirin.
Yönetim arayüzünü yalnızca güvenilir ağlardan erişilebilir hale getirin.
Çok faktörlü kimlik doğrulama (MFA), IP kısıtlamaları ve erişim günlüklerini düzenli olarak izleyin.
✅ Geçici Koruma Önlemleri
Güvenlik güncellemesi veya önerilen hafifletici önlemler uygulanamıyorsa, N-central sunucusunun internet erişimini sınırlandırın veya yalnızca VPN üzerinden erişilebilir hale getirin. Gerekirse yönetim arayüzünü geçici olarak devre dışı bırakmayı değerlendirin.
📚 Referans: N-able Security Advisory & CISA
Post summary
The bulletin announces CVE‑2026‑18556 (authentication bypass in N‑able N‑central) and focuses on recommending vendor patches, mitigations, and temporary protective steps.
🚨 CVE-2026-86218 — N-able N-central, pre-auth RCE. CVSS 10.0.
What broke: this is the remote-control tower for customer PCs. The new bug lets someone with no password run code on that tower. Own N-central and you can push scripts, open remote sessions, and touch every endpoint it manages.
Who should care: MSPs and enterprise IT running N-central — every build before 2026.3.1.14. That includes servers you just put on Hotfix 3 yesterday. Hosted N-central (NCOD) is already patched by N-able. On-prem is on you. Shadowserver still sees about 1,500 consoles on the internet.
Why that matters: August’s N-central bugs (CVE-2026-18556 / 18577) were already used to walk from the console into customer networks and leave tunnels behind. This is the third serious wave in about six weeks.
Status: N-able’s public notes say no confirmed production hits. A separate customer/incident notice called it a zero-day “observed being exploited in the wild.” Huntress flagged it as a possible zero-day too.
Not on CISA KEV yet. Responsible disclosure; no public how-to from the vendor.
Fix today: N-central 2026.3 Hotfix 4 — build 2026.3.1.14. Direct path from 2025.4, 2026.1, 2026.2, 2026.3, and HF1–HF3. Agents do not need an upgrade for this CVE.
Can't patch: take the N-central console off the public internet. Restrict it to VPN / allowlisted admin IPs. Audit admin accounts for new or odd users (Huntress also patched an auth-bypass pair over the weekend: CVE-2026-86206 / 86207).
Do this now: check the build. If it is not 2026.3.1.14, install HF4 today and reply “patched.”Source: N-able status / http://CVE.org / Help Net Security / BleepingComputer
#Nable#RMM
Post summary
N‑central within the 2026.3 line has a pre‑auth RCE (CVE‑2026‑86218) with CVSS 10.0; a hotfix is available and some reports indicate possible exploitation in the wild.
@Nable published an N-central security advisory for CVE-2026-18556 and CVE-2026-18577 on Aug 2 with 6 IOC IP addresses. We were already tracking 2 of them two months before disclosure.
CVE-2026-18577 was announced after an incomplete patch for CVE-2026-18556 was released.
The exploit grants administrator access on N-central (through 2026.3.1). It's being exploited in the wild right now.
We cross-referenced N-able's 6 published indicators against Lupovis deception telemetry.
Two matched:
• 37.19.210.32 (Datacamp): 27 recon events against our sensors
• 68.235.46.214 (tzulo): reconnaissance plus credential brute-forcing
Our earliest sighting:
May 27. Roughly two months before the advisory. The IPs in the bulletin were known for probing, enumerating and password-spraying long before anyone published a CVE number.
That's the point of Lupovis. The IOC list is the end of the story. The traffic is the start of it.
If you run N-central on-prem:
→ Upgrade to 2026.3.1.7 today
→ Block all 6 advisory IOC IPs
→ Hunt for rogue services and unexpected Cloudflare tunnels (the documented persistence method)
No public PoC exists yet. Active exploitation isn't waiting for one.
N-able's advisory (indicators and guidance): https://www.n-able.com/blog/n-central-security-update-august-2-2026
Want to block threat actors before a 0-day drops? Try our insights[dot]lupovis[dot].io platform #ThreatIntel#CVE#Ncentral#KEV#DeceptionTechnology#MSP
Post summary
N‑able issued an advisory for CVE‑2026‑18556/77 with IOC; exploitation is active, and the primary mitigation is upgrading to 2026.3.1.7 and blocking listed IPs.
🚨 CRITICAL RCE — N-ABLE HAS RELEASED AN EMERGENCY N-CENTRAL HOTFIX FOR A NEW CVSS 10 PRE-AUTHENTICATION REMOTE CODE EXECUTION FLAW
No credentials. No user interaction. Network-accessible exploitation.
CyberSignal Priority: 🔴 VERY HIGH
CVE: CVE-2026-86218
Product: N-able N-central
CVSS v4.0: 10.0 CRITICAL
Affected: versions before 2026.3.1.14
Fixed: 2026.3 HF4 / build 2026.3.1.14
Disclosure: September 6, 2026
### 🔎 What happened
N-able disclosed a new critical vulnerability in N-central today.
CVE-2026-86218 allows PRE-AUTHENTICATION REMOTE CODE EXECUTION against vulnerable N-central servers.
The CVSS vector is especially serious:
Network reachable
+
Low attack complexity
+
No privileges required
+
No user interaction
+
High confidentiality, integrity and availability impact.
N-able classifies the weakness as CWE-96 — improper neutralization of directives in statically saved code.
Technical details about the vulnerable endpoint or exact exploitation mechanism have not yet been publicly disclosed.
### 🎯 What is affected
N-central:
< 2026.3.1.14
On-premises administrators should move to:
2026.3 HF4
build 2026.3.1.14
N-able says hosted N-central environments have already received the mitigation.
Even organizations that installed HF3 need HF4 for this newly disclosed issue.
### ⚠️ Exploitation status — important distinction
There is conflicting public information.
An N-able representative said a third independent researcher reported a NEW vulnerability that had been:
“exploited in the wild.”
However, currently indexed CVE and vulnerability-tracking data do not independently confirm an exploitation campaign, and no public PoC or exploit module has been identified at this time.
Therefore:
VENDOR REPRESENTATIVE CLAIM:
Exploitation in the wild reported.
INDEPENDENT CONFIRMATION:
Not established yet.
CISA KEV:
Not listed at the time of this post.
Public PoC:
None identified.
Do NOT confuse CVE-2026-86218 with the earlier N-central vulnerabilities CVE-2026-18556, CVE-2026-18577, CVE-2026-86206 or CVE-2026-86207.
### 🛡️ Defender action
ON-PREMISES N-CENTRAL:
→ Upgrade to 2026.3 HF4 immediately
→ Confirm the actual server build is 2026.3.1.14 or later
→ Restrict N-central exposure to trusted administrative networks/IPs
→ Review recent server activity and administrative changes
→ Treat unexpected N-central server behavior as potentially high-impact
### 🧠 Why this matters
N-central is not an ordinary application.
It is a remote monitoring and management platform used to administer other systems.
That creates an asymmetric blast radius:
ONE MANAGEMENT SERVER
↓
MANY MANAGED ENDPOINTS
↓
MULTIPLE CUSTOMER ENVIRONMENTS.
A compromise of the control plane can therefore be considerably more damaging than compromise of a normal standalone server.
### 🧠 CyberSignal Insight
The CVSS 10 is only part of the story.
The more important security property is TRUST CONCENTRATION.
An attacker who compromises software designed to remotely administer fleets of machines may inherit the same authority defenders intentionally gave that platform.
That is why pre-auth RCE in an RMM management plane deserves emergency treatment even before the full exploitation picture is known.
Sources: N-able · NVD/CVE · Huntress · public N-able representative communication
Post summary
The post announces a critical pre‑authentication RCE flaw (CVE‑2026‑86218) in N‑able N‑central, details an emergency hotfix and patch procedure, notes unverified claims of wild exploitation, and urges immediate remediation steps.
🚨 CRITICAL RCE — N-ABLE HAS RELEASED AN EMERGENCY N-CENTRAL HOTFIX FOR A NEW CVSS 10 PRE-AUTHENTICATION REMOTE CODE EXECUTION FLAW
No credentials. No user interaction. Network-accessible exploitation.
CyberSignal Priority: 🔴 VERY HIGH
CVE: CVE-2026-86218
Product: N-able N-central
CVSS v4.0: 10.0 CRITICAL
Affected: versions before 2026.3.1.14
Fixed: 2026.3 HF4 / build 2026.3.1.14
Disclosure: September 6, 2026
🔎 What happened
N-able disclosed a new critical vulnerability in N-central today.
CVE-2026-86218 allows PRE-AUTHENTICATION REMOTE CODE EXECUTION against vulnerable N-central servers.
The CVSS vector is especially serious:
Network reachable
+
Low attack complexity
+
No privileges required
+
No user interaction
+
High confidentiality, integrity and availability impact.
N-able classifies the weakness as CWE-96 — improper neutralization of directives in statically saved code.
Technical details about the vulnerable endpoint or exact exploitation mechanism have not yet been publicly disclosed.
🎯 What is affected
N-central:
< 2026.3.1.14
On-premises administrators should move to:
2026.3 HF4
build 2026.3.1.14
N-able says hosted N-central environments have already received the mitigation.
Even organizations that installed HF3 need HF4 for this newly disclosed issue.
⚠️ Exploitation status — important distinction
There is conflicting public information.
An N-able representative said a third independent researcher reported a NEW vulnerability that had been:
“exploited in the wild.”
However, currently indexed CVE and vulnerability-tracking data do not independently confirm an exploitation campaign, and no public PoC or exploit module has been identified at this time.
Therefore:
VENDOR REPRESENTATIVE CLAIM:
Exploitation in the wild reported.
INDEPENDENT CONFIRMATION:
Not established yet.
CISA KEV:
Not listed at the time of this post.
Public PoC:
None identified.
Do NOT confuse CVE-2026-86218 with the earlier N-central vulnerabilities CVE-2026-18556, CVE-2026-18577, CVE-2026-86206 or CVE-2026-86207.
🛡️ Defender action
ON-PREMISES N-CENTRAL:
→ Upgrade to 2026.3 HF4 immediately
→ Confirm the actual server build is 2026.3.1.14 or later
→ Restrict N-central exposure to trusted administrative networks/IPs
→ Review recent server activity and administrative changes
→ Treat unexpected N-central server behavior as potentially high-impact
🧠 Why this matters
N-central is not an ordinary application.
It is a remote monitoring and management platform used to administer other systems.
That creates an asymmetric blast radius:
ONE MANAGEMENT SERVER
↓
MANY MANAGED ENDPOINTS
↓
MULTIPLE CUSTOMER ENVIRONMENTS.
A compromise of the control plane can therefore be considerably more damaging than compromise of a normal standalone server.
🧠 CyberSignal Insight
The CVSS 10 is only part of the story.
The more important security property is TRUST CONCENTRATION.
An attacker who compromises software designed to remotely administer fleets of machines may inherit the same authority defenders intentionally gave that platform.
That is why pre-auth RCE in an RMM management plane deserves emergency treatment even before the full exploitation picture is known.
Sources: N-able · NVD/CVE · Huntress · public N-able representative communication
Post summary
N‑Able issued an emergency hot‑fix for CVE‑2026‑86218, a critical pre‑auth RCE vulnerability; no public PoC or exploit exists and active exploitation has not been confirmed.
🚨Upozorňujeme na aktivně zneužívanou zranitelnost v nástroji pro vzdálenou správu N-able N-central, CVE-2026-18577. Zranitelnost vznikla v důsledku neúplné opravy zranitelnosti CVE-2026-18556 a umožňuje vzdálenému neautentizovanému útočníkovi obejít ověřování a získat administrátorskou kontrolu nad zasaženým serverem N-central. Vzhledem k tomu, že platforma slouží pro vzdálenou správu koncových zařízení, může úspěšné zneužití vést k převzetí spravovaných systémů, zneužití funkce Take Control pro vzdálený přístup, vytvoření perzistence prostřednictvím nástroje Cloudflare Tunnel (cloudflared) a dalšímu šíření kompromitace v prostředí organizace. Zranitelnost je podle výrobce aktivně zneužívána od 1. srpna 2026 a byla zařazena do katalogu známých zneužívaných zranitelností CISA KEV. Postiženy jsou verze N-able N-central starší než 2026.3.1.7.
Mezi indikátory kompromitace patří přítomnost služby cloudflared, podezřelý soubor svchost.exe umístěný ve složce Documents uživatele, vytvoření nebo úpravy administrátorských účtů, neobvyklá aktivita funkcionality Take Control, instalace nových služeb Windows a komunikace s IP adresami 173.249.252[.]176, 173.249.252[.]200, 185.156.46[.]150, 23.234.94[.]43, 37.153.90[.]88, 37.19.210[.]32, 68.235.46[.]214, 68.235.46[.]235, 87.249.138[.]34 a 92.118.112[.]181.
📌Doporučujeme aktualizovat na verzi 2026.3.1.10 (Hotfix 2), prověřit systémy na přítomnost indikátorů kompromitace a zkontrolovat autentizační logy, změny administrátorských účtů, aktivitu Take Control a komunikaci s publikovanými IoC adresami.
Post summary
The post alerts that CVE‑2026‑18577 is actively exploited in the wild, lists indicators of compromise, and recommends a specific patch, underscoring an ongoing attack campaign.
The ThreatLocker Threat Intelligence Team analyzed the advisory released by N-able for CVE-2026-18556, affecting version 2026.1 of their RMM platform, N-central.
CVE-2026-18556 is an authentication bypass flaw in N-central that affects both on-premises and cloud deployments. Attackers could gain administrative access, execute scripts, automate jobs, modify configurations, and potentially impact downstream customers. Although exploitation details have not been released, the disclosed impact is severe.
Mitigation steps to follow:
-Patch all N-central servers to 2026.3.1.7 immediately
-Take unpatched servers offline
-Restrict public N-central console access
-Review admin accounts and permissions
-Revoke suspicious account access
-Audit logs for remote access, scripts, and jobs
-Hunt for Cloudflared and svchost.exe
-Check network logs against listed IOCs
To read the full breakdown: https://www.threatlocker.com/blog/n-able-n-central-vulnerability-grants-unauthenticated-users-god-mode
Post summary
The post alerts on a severe authentication bypass in N‑central, provides a patch (version 2026.3.1.7) and mitigation steps, but offers no exploitation details or PoC.
CVE-2026-86218, a critical pre-auth RCE in N-able N-central, is patched in build 2026.3.1.14 (HF4). Two earlier flaws, CVE-2026-18556 and CVE-2026-18577, are in CISA KEV as actively exploited.
#DFIR_Radar https://t.co/dPAXzompjp
Post summary
The message announces that CVE-2026-86218, a critical pre-auth RCE in N-able N-central, has been patched in build 2026.3.1.14 (HF4), and notes that two earlier CVEs are listed in the CISA KEV as actively exploited.
The CVEs 2026‑18577/18556 in N‑able N‑central have been confirmed as exploited in the wild, enabling authentication bypass and potential administrative takeover. A patch has been released; users should install it immediately and monitor for suspicious activity.
DEEP DIVE — CVE-2026-18556: unauthenticated auth bypass in N-able N-central, KEV-listed and exploited in the wild. Patched to 2026.2 back in April? Still exploitable, the fix was incomplete. Only build 2026.3.1.10 is current. https://t.co/Kq3nyV0OZN
Post summary
CVE-2026-18556, an unauthenticated authentication bypass in N‑able N‑central, is KEV‑listed and actively exploited; current vendor patches reach only build 2026.3.1.10, leaving earlier versions vulnerable.
2/3 CVE-2026-18577 (CVSS 8.2) hits every N-central version before 2026.3.1.7. It was found under exploitation on July 31 and is an incomplete fix for CVE-2026-18556, so the first patch left a gap attackers kept using to persist. #InfoSec#CVE#CyberAttack
Post summary
CVE‑2026‑18577 remains exploitable in N‑central versions older than 2026.3.1.7; an incomplete patch created a maintenance window that attackers exploited, and the vulnerability is actively used in the wild.
CVE-2026-18556 and CVE-2026-18577 (CVSS 8.2) in N-able N-central are actively exploited, giving attackers unauthenticated admin access to RMM servers and every downstream managed endpoint.
- Two auth bypass flaws let an unauthenticated remote attacker gain full administrative control of N-central. N-able confirmed active exploitation on Aug 1, 2026. The first clean build is 2026.3.1.7; upgrading only to 2026.3 is NOT sufficient, as CVE-2026-18577 persisted through 2026.3.1.
- Attackers abused N-central's built-in Take Control feature to reach managed endpoints, then registered a Cloudflare tunnel service for persistent access. Persistence lives on the downstream endpoint, not the RMM server, so patching N-central alone does not evict an attacker already inside.
- Hunt for unexpected cloudflared services or svchost.exe running from a user's Documents folder. Review N-central ui_access_control.log and endpoint logs at C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz for unaccountable Take Control sessions, especially tied to apparent N-able support identities.
- Published IOCs include IPs 173.249.252[.]200, 87.249.138[.]34, 37.19.210[.]32, 37.153.90[.]88, 92.118.112[.]181, 68.235.46[.]214 and domains mousears.synology[.]me and http://wagoosh.direct.quickconnect[.]to. Huntress notes the first four IPs are Mullvad/NordVPN exit nodes, so treat blocking as partial only.
#DFIR_Radar
Post summary
The N‑able N‑central vulnerabilities CVE‑2026‑18556 and CVE‑2026‑18577 are actively exploited in the wild, allowing unauthenticated admin access and persistence via Take Control with a Cloudflare tunnel. Patch to build 2026.3.1.7 is required, and monitoring for specific IOCs is recommended.
🛡️ BOLLETTINO CYBER | 06/08/2026
1. Vulnerabilità critica in JetBrains TeamCity in sfruttamento attivo
CSIRT Italia e CISA segnalano la CVE-2026-63077 (CVSS 9.8): RCE non autenticata su tutte le versioni on-premise di TeamCity tramite il protocollo agent polling. Aggiornare subito alle versioni 2025.11.7 o 2026.1.3 (o applicare il plugin di sicurezza).
2. ChainDrop: worm auto-propagante colpisce oltre 400 pacchetti npm
Campagna supply-chain identificata da CSIRT Italia che compromette pacchetti ampiamente usati (keyv, flat-cache e altri) con oltre 2 miliardi di download mensili. Il malware ruba credenziali e si propaga automaticamente. Controllare immediatamente le dipendenze e i lockfile.
3. CISA: vulnerabilità sfruttate in Langflow, N-central e Apache Tomcat
Tre flaw aggiunti al KEV catalog (CVE-2026-9198, CVE-2026-18556/18577 e CVE-2026-34486). Consentono RCE, bypass di autenticazione e altre compromissioni. Le agenzie federali USA hanno solo pochi giorni per mettere in sicurezza i sistemi.
4. Creatore di Ransom Cartel condannato a 16 anni di carcere
Maksim Silnikau, fondatore del ransomware-as-a-service attivo dal 2021, è stato condannato negli USA. L’operazione ha colpito almeno 18 aziende in più paesi. Un segnale importante nella lotta al RaaS.
Priorità assoluta: patchare TeamCity e verificare le supply chain npm.
#Cybersecurity#CyberItalia
Post summary
JetBrains TeamCity suffers an actively exploited RCE (CVE‑2026‑63077) and the advisory urgently recommends applying the latest patches; the text highlights active exploitation and patch‑remediation.