Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-08-06. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Active Exploitation31Disclosure1Exploit1General2Patch5
2026-08-05
15
Active Exploitation8Disclosure1General3Patch2PoC1
2026-08-06
6
Active Exploitation4Patch2
2026-08-07
7
Active Exploitation5Patch2
2026-08-08
10
Active Exploitation8Patch2
2026-08-09
7
Active Exploitation6Disclosure1
2026-08-10
20
Active Exploitation10General1Patch9
2026-08-11
9
Active Exploitation7Patch2
2026-08-12
3
Active Exploitation3
2026-08-13
2
Active Exploitation2
2026-08-19
1
Active Exploitation1
2026-08-21
1
Disclosure1
2026-08-26
1
Disclosure1
2026-08-27
1
Patch1
2026-09-01
1
General1
2026-09-02
1
Disclosure1
2026-09-06
2
Patch2
2026-09-08
2
Patch2
2026-09-09
1
Active Exploitation1
2026-09-10
1
Patch1
>Full discourse20 posts
The Hacker News@TheHackersNews·
Active Exploitation
⚠️ N-central attacks are reaching managed endpoints.
Attackers are exploiting CVE-2026-18577 to bypass authentication, gain admin access, and abuse Take Control for lateral movement. N-able confirms limited customer compromises, and CISA has added the flaw to KEV.
What defenders need to check: https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
Post summary
Attackers are actively exploiting CVE-2026-18577 to bypass authentication in N-central, with CISA listing it as a KEV, confirming real‑world usage.
🚨 China-linked Storm-1175 deploys previously undocumented StormEncryptor ransomware.
Microsoft says the group has shifted from Medusa and likely used N-able N-central CVE-2026-18577 for initial access. Storm-1175 has been observed moving from initial access to data exfiltration and ransomware deployment within days.
Inside the campaign → https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
Post summary
The China-linked Storm-1175 group is actively exploiting CVE-2026-18577 to gain initial access, then proceeding to data exfiltration and ransomware deployment.
While researching last months N-able N-central exploit (CVE-2026-18577, on KEV), we found and reported a new authentication bypass chain (CVE-2026-86206 and CVE-2026-86207). Patched and disclosed by the vendor over the weekend, we have published full details on the @rapid7 blog: https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/
Post summary
N-able N-central authentication bypass vulnerabilities CVE-2026-86206 and CVE-2026-86207 were discovered, patched by the vendor, and fully documented on a Rapid7 blog post.
🛡️We added N-able N-central authentication bypass vulnerability CVE-2026-18577 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity#InfoSec https://t.co/Vvye9o8g51
Post summary
CVE‑2026‑18577, an authentication bypass in N‑able N‑central, is listed in the DHS KEV catalog, indicating it is being exploited in the wild. The post urges users to apply available mitigations to protect against potential attacks.
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild
Post summary
CVE-2026-18577 is an authentication bypass vulnerability in N‑able N‑central that has been reported as actively exploited in the wild, per a Rapid7 blog post.
Daniel's Daily Threat Intel & CVE Briefing — Fri 7 Aug 2026
Top of the stack: Today is CISA's federal remediation due date for the N-able N-central / Langflow / Tomcat KEV batch — and the N-central bug is the one that matters: CVE-2026-18577, an auth-bypass that is a bypass of the incomplete fix for CVE-2026-18556, is being exploited in the wild since Aug 1 to seize admin on RMM servers and pivot into managed endpoints. If you or clients run N-central, patch to 2026.3.1 Hotfix 1 (2026.3.1.7) and hunt for post-compromise activity before anything else today.
1. CISA KEV / actively exploited (lead)
CVE-2026-18577 — N-able N-central, all versions ≤ 2026.3.1 (pre-Hotfix 1). Unauth auth-bypass → full admin. Exploited in the wild from Aug 1; added to KEV Aug 3. Post-exploit TTPs: abuse of the Take Control feature to reach managed endpoints + Cloudflare Tunnel for persistent backdoor. Fix: 2026.3.1.7. So what: RMM = one box to own the whole estate; treat any unpatched N-central as presumed-compromised.
CVE-2026-18556 — N-able N-central auth-bypass (the incompletely-patched precursor to 18577), CVSS 8.2. KEV, federal due date today.
CVE-2026-9198 — Langflow (open-source AI app-dev platform), CVSS 9.8, unauth code-injection → RCE. Fixed 1.10.1. Repeatedly weaponized in recent months; KEV, due today. So what: internet-exposed AI/LLM tooling is now a routine initial-access target.
CVE-2026-34486 — Apache Tomcat, CVSS 7.5, EncryptInterceptor cluster-messaging bypass. Fixed 11.0.21 / 10.1.54 / 9.0.117. Tied to SNOWLIGHT malware campaign; KEV, due today.
CVE-2026-63077 — JetBrains TeamCity deserialization flaw, added to KEV this week. Verify your CI/CD estate isn't exposing TeamCity to untrusted networks.
2. Edge / network gear
CVE-2026-20316 — Cisco Secure Firewall Management Center (FMC) 7.0–7.7 / 10.0. Static credentials for a low-priv account → unauth remote access to sensitive data; actively exploited as a zero-day (disclosed Jul 30). Base CVSS only 5.3 but Cisco rates SIR High because it's chainable for privilege escalation. So what: not the headline score, but it's live and it's your firewall manager — patch and rotate.
Fortinet/Ivanti criticals (FortiSandbox CVE-2026-25089 9.8; Ivanti Sentry CVE-2026-10520 10.0 / CVE-2026-10523 9.9) are from the June 10 cycle — no new exploitation reported in the last 24–48h; flagged only in case anything remains unpatched.
3. Microsoft / Windows / AD
Quiet in the last 24h. No new in-the-wild Windows/AD/Exchange/Entra items surfaced. August Patch Tuesday lands Aug 11 — July's record 622-flaw cycle (2 zero-days under active attack) should already be deployed; if not, that's your gap.
4. Web / cloud / DevOps
CVE-2026-66066 — Rails Active Storage (< 7.2.3.2, 8.0.x < 8.0.5.1, 8.1.x < 8.1.3.1; 6.x only if configured off-default). Critical; unauth arbitrary file read → potential RCE via libvips ("KindaRails2Shell", pivots on the app master key). Public PoC available (disclosed Aug 1). Mitigation: upgrade Rails/Active Storage, libvips ≥ 8.13, ruby-vips ≥ 2.2.1.
CVE-2026-63030 + CVE-2026-60137 — WordPress core "wp2shell" chain (REST batch-route confusion + author__not_in SQLi). Unauth RCE on default installs 6.9.0–6.9.4 / 7.0.0–7.0.1. Public exploits on GitHub; watchTowr reports in-the-wild exploitation. Fixed 6.9.5 / 7.0.2 (forced auto-update pushed). Slightly older (Jul 18) but still actively exploited — worth a scan sweep.
Watch / developing
Oracle out-of-band Security Alert CVE-2026-35273 surfaced this week — details thin, worth confirming scope. Senserva notes ~30 KEV entries this month with 2 tied to ransomware campaigns (Microsoft/Fortinet/Cisco most-affected) — watch for ransomware operators folding the N-central and Langflow bugs into their access-broker playbooks.
Sign-off: 7 items flagged actively exploited today (N-central ×2, Langflow, Tomcat, TeamCity, Cisco FMC, WordPress wp2shell); the single must-do is patching N-central before CISA's due date closes.
Sources:
CISA — Adds Three KEVs (Aug 4)
CISA — Adds One KEV (Aug 3)
The Hacker News — CISA flags Langflow, Tomcat, N-central
Rapid7 — CVE-2026-18577 N-central exploited in the wild
N-able — N-central Security Update (Aug 2)
The Hacker News — Cisco FMC zero-day actively exploited
BleepingComputer — Rails Active Storage RCE (CVE-2026-66066)
BleepingComputer — WordPress wp2shell RCE public exploits
SecurityWeek — Fortinet/Ivanti critical patches
Senserva — CISA KEV additions this week
One caveat worth noting for your own verification: NVD detail pages were unreachable during this run, so severities above are corroborated against vendor advisories, CISA, and reputable trackers rather than NVD directly — the Langflow 9.8 and Cisco 5.3 figures each have two independent sources, but confirm against NVD before citing formally.
Post summary
The briefing highlights several CVEs—particularly CVE‑2026‑18577 and others—actively being exploited in the wild, provides PoCs, patches, and detailed technical information, underscoring an urgent need for remediation.
🚩 StormEncryptor Emerges in New Storm-1175 Campaign
https://cyberpress.org/storm-1175-deploys-new-stormencryptor-ransomware/
The Storm-1175 threat group is back, this time with a new ransomware family called StormEncryptor.
The campaign began August 2 and may be linked to exploitation of CVE-2026-18577, an authentication bypass affecting N-able products.
After gaining access, the group has used AnyDesk and SimpleHelp, scanned internal networks, dumped credentials with Mimikatz, and moved toward data theft and encryption.
#ThreatIntel#Storm1175#Ransomware#CyberSecurity
Post summary
The post announces the emergence of StormEncryptor into a Storm-1175 ransomware campaign, mentioning a potential exploit of CVE-2026-18577, but lacks concrete evidence of active exploitation, PoC, or mitigation details.
CISA confirms active exploitation of Langflow, N-central and Apache Tomcat vulnerabilities
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, confirming evidence of exploitation in real attacks:
⚠️ CVE-2026-9198: Critical unauthenticated remote-code execution in IBM Langflow OSS.
⚠️ CVE-2026-18577: Authentication bypass affecting N-able N-central.
⚠️ CVE-2025-24813: Apache Tomcat flaw capable of enabling remote code execution or information disclosure under vulnerable configurations.
Federal civilian agencies were given an unusually short three-day remediation deadline, reflecting the immediate risk.
#DDW#DarkWeb#Vulnerabilities#CISA
Source: https://www.cisa.gov/news-events/alerts/2026/08/04/cisa-adds-three-known-exploited-vulnerabilities-catalog
Post summary
CISA reports that CVE‑2026‑9198, CVE‑2026‑18577, and CVE‑2025‑24813 are actively exploited in real attacks, highlighting immediate remediation needs.
🚨 Active exploitation: N-able N-central (CVE-2026-18577)
Sophos X-Ops is tracking in-the-wild exploitation of a critical auth bypass in N-able N-central, hit as a zero-day since July 31. https://t.co/E3OuL01iAI
Post summary
Sophos X‑Ops reports that CVE‑2026‑18577, a critical authentication bypass in N‑able N‑central, has been actively exploited in the wild since July 31, with no patch or workaround cited yet.
CVE‑2026‑18577 is a critical authentication bypass in N‑able N‑central that has been confirmed as actively exploited by attackers, as reported by Huntress. A vendor hotfix and mitigation steps are available.
This morning N-able have released a second CVE (CVE-2026-18577)
Due to an incomplete patch in the first (CVE-2026-18556)
Unauth admin account takeover
Post summary
N‑able announced a second CVE (CVE‑2026‑18577) stemming from an incomplete patch to the first vulnerability, enabling unauthenticated administrative account takeover.
Breaking: N-able advierte a sus clientes que los hackers están explotando una vulnerabilidad de bypass de autenticación (CVE-2026-18577) que afecta a los servidores N-central, tanto alojados como locales.
N-able es el objetivo, con una vulnerabilidad que permite a los atacantes saltarse la autenticación en los servidores N-central. La empresa ha emitido una advertencia a sus clientes sobre esta vulnerabilidad activamente explotada.
La vulnerabilidad, identificada como CVE-2026-18577, permite a los atacantes acceder a los servidores N-central sin necesidad de credenciales válidas.
Los clientes deben tomar medidas para protegerse, como monitorear sus servidores y redes para detectar cualquier actividad sospechosa.
¿Estás en riesgo? Revisa esto: asegúrate de que tus servidores N-central estén actualizados y monitorea tus redes para detectar cualquier actividad maliciosa.
#Ciberseguridad#CVE#SeguridadDigital#RedSegura
https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-flaw-exploited-in-attacks/
Post summary
Hackers are actively exploiting CVE-2026-18577, an authentication bypass in N‑Central servers; users are urged to patch and monitor their systems.
🚨 CVE-2026-18577 - critical 🚨
N-able N-central < 2026.3.1.10 - Authentication Bypass
> N-able N-central versions through 2026.3.1 contain an authentication bypass that lets...
👾 https://cloud.projectdiscovery.io/library/CVE-2026-18577
@pdnuclei#NucleiTemplates#cve
Post summary
The post announces a critical authentication bypass vulnerability in N‑able N‑central versions up to 2026.3.1 and links to a ProjectDiscovery resource, but does not mention active exploitation, patches, or exploit code.
🔴 Patch Now | August 27, 2026
Bringing these CVEs to your attention:
- Azure Active Directory (CVE-2026-50481, CVSS 9.9)
- Windows AD Certificate Services (CVE-2026-62818, CVSS 8.8)
- N-able N-central (CVE-2026-18577)
#CyberSafeUG#CERTUGCC https://t.co/k8OQLM3Y0f
Post summary
The tweet urges urgent patching of three high‑severity CVEs affecting Azure AD, Windows AD Certificate Services, and N‑Able N‑central, with no evidence of PoC, exploitation tools, or ongoing attacks.
🖥️ N-able N-central CVE-2026-18577 vulnerability analysis
CVE-2026-18577 is a critical authentication bypass vulnerability affecting N-able N-central, an RMM platform used by MSPs and enterprise IT teams. Attackers can access the management environment without valid credentials and abuse legitimate remote management functions to move into connected systems.
🔎 Criminal IP findings:
• N-central management interfaces were identifiable from the public Internet
• Product names and login-related responses exposed clear N-central fingerprints
• HTTP 200 responses confirmed that some management interfaces were actively reachable
Organizations should patch immediately, restrict external access, and review remote management activity for compromise.
📌 Read the full analysis:
https://www.criminalip.io/knowledge-hub/blog/37044
#Nable#Ncentral#CVE202618577#RMM#ThreatIntelligence#Cybersecurity
Post summary
The tweet highlights a critical authentication bypass in N-able N‑central and strongly urges immediate patching, without providing proof of exploit or indicating active attacks.
N-able N-central Emergency Patch
CVE-2026-18577 is currently being actively exploited. Attackers could gain full admin access to the N-central console and further control the managed endpoints.
Key affected cases: Instances before 2026.3 that are exposed to the Internet or accessible from untrusted networks.
Post summary
CVE-2026-18577 is being actively exploited, allowing attackers full admin and endpoint control; an emergency patch is available for affected instances exposed to untrusted networks.
@Nable published an N-central security advisory for CVE-2026-18556 and CVE-2026-18577 on Aug 2 with 6 IOC IP addresses. We were already tracking 2 of them two months before disclosure.
CVE-2026-18577 was announced after an incomplete patch for CVE-2026-18556 was released.
The exploit grants administrator access on N-central (through 2026.3.1). It's being exploited in the wild right now.
We cross-referenced N-able's 6 published indicators against Lupovis deception telemetry.
Two matched:
• 37.19.210.32 (Datacamp): 27 recon events against our sensors
• 68.235.46.214 (tzulo): reconnaissance plus credential brute-forcing
Our earliest sighting:
May 27. Roughly two months before the advisory. The IPs in the bulletin were known for probing, enumerating and password-spraying long before anyone published a CVE number.
That's the point of Lupovis. The IOC list is the end of the story. The traffic is the start of it.
If you run N-central on-prem:
→ Upgrade to 2026.3.1.7 today
→ Block all 6 advisory IOC IPs
→ Hunt for rogue services and unexpected Cloudflare tunnels (the documented persistence method)
No public PoC exists yet. Active exploitation isn't waiting for one.
N-able's advisory (indicators and guidance): https://www.n-able.com/blog/n-central-security-update-august-2-2026
Want to block threat actors before a 0-day drops? Try our insights[dot]lupovis[dot].io platform #ThreatIntel#CVE#Ncentral#KEV#DeceptionTechnology#MSP
Post summary
N‑able’s advisory for CVE‑2026‑18556/18577 reports active exploitation and urges users to upgrade to 2026.3.1.7 and block IOC IPs, with no public PoC yet.