A critical zero-day vulnerability, designated as CVE-2026-18577, in N-able's N-central platform has been exploited by attackers, resulting in unauthorized access to customer networks. The vulnerability allows unauthenticated attackers to gain administrative access to the remote monitoring and management platform, which was then used to connect to internal systems using the Take Control feature. N-able has released a second mandatory hotfix to address the issue, following an initial fix, in an effort to mitigate the damage. The exploit has significant implications, as it expands the active attack surface, making it essential for organizations to prioritize their response based on exposure and evidence of exploitation1. This incident highlights the importance of prompt patching and vigilance in protecting against potential attacks, particularly for those with vulnerable N-central servers.
N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
⚠️ Critical Alert
Why This Matters
CVE-2026-18577 disclosure expands the active attack surface — prioritize based on your exposure and exploitation evidence.
References
- The Register. (2026, August 7). N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands. *The Register*. https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730
Original Source
The Register
Read original →