CYBERSECURITYTRACKER
TRACKING6,902 stories in this site build1,444 vulnerability news stories in this site build
Permanent story citation

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3703

As cited

Copy frozen at (site build).

vulnerabilities

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able disclosed that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-central to obtain remote administrative access to the platform and systems managed through it. An initial patch released on August 2, 2026 proved incomplete, allowing continued exploitation. The vulnerability affects N-central builds prior to version 2026.3.1.7.

Why it matters: Managed service providers and their customers face potential compromise of monitored infrastructure; practitioners managing N-central deployments must verify they have deployed the complete fix and audit for unauthorized administrative access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able disclosed that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-central to obtain remote administrative access to the platform and systems managed through it. An initial patch released on August 2, 2026 proved incomplete, allowing continued exploitation. The vulnerability affects N-central builds prior to version 2026.3.1.7.

Why it matters: Managed service providers and their customers face potential compromise of monitored infrastructure; practitioners managing N-central deployments must verify they have deployed the complete fix and audit for unauthorized administrative access.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary