Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-central Servers Breached: Authentication Flaw Exploited

N-central Servers Breached: Authentication Flaw Exploited

Posted on August 3, 2026 By CWS

N-able has confirmed a breach of its N-central servers after attackers exploited an authentication bypass vulnerability, allowing them unauthorized remote administrative access. This incident, which impacts customer systems managed by these servers, underscores significant security concerns for users of the N-central platform.

Flaw Exploitation and Response

The vulnerability, identified as CVE-2026-18577, affects N-central builds prior to version 2026.3.1.7. N-able released this secure build on August 2, following the realization that their initial fix was insufficient. This platform, widely used by managed service providers and IT teams, is crucial for administering customer endpoints remotely.

Compromised servers enabled attackers to deploy ‘Take Control’ for access to managed endpoints, registering Cloudflare tunnels as services on the devices. These tunnels require no inbound firewall rules, thereby maintaining persistent access even after the initial server route is revoked.

Security Measures and Recommendations

N-able advises all N-central users to upgrade to version 2026.3.1.7 immediately. The previously recommended upgrade to version 2026.3 is now deemed inadequate. Hosted NCOD instances will receive automatic updates, while self-hosted servers need manual upgrades by customers.

In cases of suspected compromise, N-able recommends a thorough search and removal of malicious tunnel services from affected endpoints. Simply upgrading the N-central server is insufficient to clear these persistent threats.

Investigation and Ongoing Concerns

Investigations began on July 31, prompted by unusual licensing errors reported by on-premises customers. The vulnerability, previously recorded as CVE-2026-18556, was thought to be resolved in version 2026.2. However, a new exploitation path was discovered, leading to the reclassification and expansion of affected versions.

The Finnish national cybersecurity center corroborated the vulnerability of all versions before the emergency patch. N-able has released a list of six IP addresses associated with the attacks, which Huntress later identified as VPN exit nodes.

Huntress has also identified domain names used by attackers and highlighted the need for customers to review logs for unauthorized access indications. The firm noted that, in one instance, attackers accessed multiple organizations under a single partner account, though the activity appeared limited to process enumeration.

N-able has yet to disclose the full scope of affected customers or data compromised. The ongoing investigation aims to clarify these details and prevent further security breaches.

The Hacker News Tags:authentication bypass, Cloudflare, CVE-2026-18577, Cybersecurity, endpoint security, Huntress, IT security, Mullvad VPN, N-able, N-central, NordVPN, remote access, Take Control, Vulnerability

Post navigation

Previous Post: SabPaisa Enhances Security with AccuKnox’s AI Cloud Technology
Next Post: MacSync Malware Targets Mac Users with Fake Guide

Related Posts

Microsoft Fixes 59 Security Flaws, Including Six Critical Zero-Days Microsoft Fixes 59 Security Flaws, Including Six Critical Zero-Days The Hacker News
WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide The Hacker News
Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time Rust Adoption Drives Android Memory Safety Bugs Below 20% for First Time The Hacker News
New Malspam Campaign Exploits Google DoubleClick New Malspam Campaign Exploits Google DoubleClick The Hacker News
Enhancing Security: From Visibility to Validation Enhancing Security: From Visibility to Validation The Hacker News
Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits Critical Dahua Camera Flaws Enable Remote Hijack via ONVIF and File Upload Exploits The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats
  • Google Eliminates AI Workflows Over GitHub Security Flaw
  • Keyv npm Package Breach in Major Supply Chain Attack
  • Obsidian Security Secures $85M, Hits $1.1B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Cybercriminals Exploit AI for Sophisticated Scams
  • AI Chatbots’ Vulnerability to Account Hijacking Threats
  • Google Eliminates AI Workflows Over GitHub Security Flaw
  • Keyv npm Package Breach in Major Supply Chain Attack
  • Obsidian Security Secures $85M, Hits $1.1B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark