Overview
- N-able released hotfix 2026.3.1.7 on August 2 to address CVE-2026-18577, an authentication-bypass that emerged after an earlier fix for CVE-2026-18556 proved incomplete.
- The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on Monday and urged federal agencies to apply the fix by August 6.
- After taking admin access to N-central consoles, attackers used the product’s Take Control feature to reach managed devices and registered Cloudflare 'cloudflared' tunnels as services to survive reboots and preserve remote access.
- N-able published indicators for defenders including specific IP addresses, a service named Cloudflared, and a file called svchost.exe found in users’ Documents folders, but hosted N-central instances are being auto-upgraded while self-hosted servers must be patched manually.
- Security vendor telemetry shows many reachable N-central servers remain unpatched, leaving MSPs and their customers exposed and creating an urgent need to hunt for tunnel persistence, review Take Control logs, and audit recent account and automation changes.