Do you have an incident?

Our S.O.S. line:

+49 89 262 025954

Our team of experts is ready to assist your organization in the event of a cyberattack.

details

N-able N-central – Take Control Taken Over

Penetration Testing WhiteHat todayAugust 7, 2026

Background

 

CVE-2026-18577-N-able N-central

Critical vulnerability has been found with the CVSS score of 8.2 in CVE-2026-18577.

Our CVE of the Week is about N-able N-central which provides customizations, automation, and integration to help your IT departments manage and secure your business. It is an ideal solution for large networks looking to scale IT operations.

The vulnerability is a case of incomplete patching for CVE-2026-18556 that allows authentication bypass and account takeover in vulnerable versions of the software. The issue has been addressed in version 2026.3 HF1.

CISA stated regarding the vulnerability:

“N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass and account takeover in N-central”

When the vulnerability is exploited successfully, it can permit remote attackers to gain administrative access to vulnerable N-central servers and then abuse the built-in Take Control feature to pivot into managed endpoints and deploy persistence mechanisms.

Indicators of Compromise (IoC)

IP addresses:

  • 173.249.252[.]200
  • 87.249.138[.]34
  • 37.19.210[.]32
  • 68.235.46[.]214

Review the endpoints for suspicious svchost.exe file located in user Documents folders and for the presence of the cloudflared service, which has been observed as a persistence mechanism in attacks exploiting this vulnerability.

Administrators should consider reviewing historical Take Control sessions for any unauthorized access attempts and investigate unexpected administrative activity on N-central servers.

With active exploitation observed in the wild and inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog, organizations using N-able N-central should prioritize remediation and incident hunting activities immediately.

Also Federal Civilian Executive Branch (FCEB) agencies are being recommended to apply the fixes by August 6, 2026, and review N-central Take Control activity in their environment.

For more information, see the vendor advisory or CISA’s article below:
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog


Do you want to be protected from attacks like the above? See our defensive services here: Managed Security – White Hat IT Security

Written by: WhiteHat

Tagged as: , , , .

Previous post

Similar posts

Penetration Testing WhiteHat / August 21, 2026

From Auto-Login to Full RCE: Inside the IBM Langflow CVE

AI has been a hotspot for everything recently and that’s true for attacks too proven by the recently discovered and also exploited IBM Langflow OSS (versions 1.0.0 through 1.10.0) vulnerability CVE-2026-9198, our #CVEoftheWeek. The issue was addressed in the release of version 1.10.1 on 24th June, which contained many security updates, but known Proof-of-Concepts (PoC) ...

Read more trending_flat