negativeSYS.SOURCE: The Hacker News• 2026-08-03T12:11:46+05:30
N-able Reports Persistent Security Breach in N-central Platform Despite Initial Patch
N-able reported that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-central, allowing remote administrative access and persistent Cloudflare tunnel-based access despite an initial incomplete patch. Customers are advised to upgrade to 2026.3.1.7 and remove malicious services to mitigate risks.
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.
N-central is the remote monitoring and management platform
*** END OF TRANSMISSION ***