Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-central Servers Breached: Authentication Flaw Exploited

N-central Servers Breached: Authentication Flaw Exploited

Posted on August 3, 2026 By CWS

N-able has confirmed a breach of its N-central servers after attackers exploited an authentication bypass vulnerability, allowing them unauthorized remote administrative access. This incident, which impacts customer systems managed by these servers, underscores significant security concerns for users of the N-central platform.

Flaw Exploitation and Response

The vulnerability, identified as CVE-2026-18577, affects N-central builds prior to version 2026.3.1.7. N-able released this secure build on August 2, following the realization that their initial fix was insufficient. This platform, widely used by managed service providers and IT teams, is crucial for administering customer endpoints remotely.

Compromised servers enabled attackers to deploy ‘Take Control’ for access to managed endpoints, registering Cloudflare tunnels as services on the devices. These tunnels require no inbound firewall rules, thereby maintaining persistent access even after the initial server route is revoked.

Security Measures and Recommendations

N-able advises all N-central users to upgrade to version 2026.3.1.7 immediately. The previously recommended upgrade to version 2026.3 is now deemed inadequate. Hosted NCOD instances will receive automatic updates, while self-hosted servers need manual upgrades by customers.

In cases of suspected compromise, N-able recommends a thorough search and removal of malicious tunnel services from affected endpoints. Simply upgrading the N-central server is insufficient to clear these persistent threats.

Investigation and Ongoing Concerns

Investigations began on July 31, prompted by unusual licensing errors reported by on-premises customers. The vulnerability, previously recorded as CVE-2026-18556, was thought to be resolved in version 2026.2. However, a new exploitation path was discovered, leading to the reclassification and expansion of affected versions.

The Finnish national cybersecurity center corroborated the vulnerability of all versions before the emergency patch. N-able has released a list of six IP addresses associated with the attacks, which Huntress later identified as VPN exit nodes.

Huntress has also identified domain names used by attackers and highlighted the need for customers to review logs for unauthorized access indications. The firm noted that, in one instance, attackers accessed multiple organizations under a single partner account, though the activity appeared limited to process enumeration.

N-able has yet to disclose the full scope of affected customers or data compromised. The ongoing investigation aims to clarify these details and prevent further security breaches.

The Hacker News Tags:authentication bypass, Cloudflare, CVE-2026-18577, Cybersecurity, endpoint security, Huntress, IT security, Mullvad VPN, N-able, N-central, NordVPN, remote access, Take Control, Vulnerability

Post navigation

Previous Post: SabPaisa Enhances Security with AccuKnox’s AI Cloud Technology
Next Post: MacSync Malware Targets Mac Users with Fake Guide

Related Posts

SkillCloak Evades AI Scanners with New Techniques SkillCloak Evades AI Scanners with New Techniques The Hacker News
Zbtlink Routers Expose Security Flaw with Built-in Backdoor Zbtlink Routers Expose Security Flaw with Built-in Backdoor The Hacker News
WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately WinRAR Zero-Day Under Active Exploitation – Update to Latest Version Immediately The Hacker News
Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks Kimwolf Android Botnet Infects Over 2 Million Devices via Exposed ADB and Proxy Networks The Hacker News
Oracle E-Business Suite Flaw Exploited Vulnerability Oracle E-Business Suite Flaw Exploited Vulnerability The Hacker News
SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Malware Evolves Hourly to Evade Detection
  • Microsoft Updates Address AI and Cloud Vulnerabilities
  • Plugin4Shell Exploit Threatens AI Coding Tools
  • Security Flaw Exposes OpenAI Code via AI-Generated Exploit
  • Brevo Attack Compromises Over 100,000 WordPress Sites

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark