Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-central Servers Breached: Authentication Flaw Exploited

N-central Servers Breached: Authentication Flaw Exploited

Posted on August 3, 2026 By CWS

N-able has confirmed a breach of its N-central servers after attackers exploited an authentication bypass vulnerability, allowing them unauthorized remote administrative access. This incident, which impacts customer systems managed by these servers, underscores significant security concerns for users of the N-central platform.

Flaw Exploitation and Response

The vulnerability, identified as CVE-2026-18577, affects N-central builds prior to version 2026.3.1.7. N-able released this secure build on August 2, following the realization that their initial fix was insufficient. This platform, widely used by managed service providers and IT teams, is crucial for administering customer endpoints remotely.

Compromised servers enabled attackers to deploy ‘Take Control’ for access to managed endpoints, registering Cloudflare tunnels as services on the devices. These tunnels require no inbound firewall rules, thereby maintaining persistent access even after the initial server route is revoked.

Security Measures and Recommendations

N-able advises all N-central users to upgrade to version 2026.3.1.7 immediately. The previously recommended upgrade to version 2026.3 is now deemed inadequate. Hosted NCOD instances will receive automatic updates, while self-hosted servers need manual upgrades by customers.

In cases of suspected compromise, N-able recommends a thorough search and removal of malicious tunnel services from affected endpoints. Simply upgrading the N-central server is insufficient to clear these persistent threats.

Investigation and Ongoing Concerns

Investigations began on July 31, prompted by unusual licensing errors reported by on-premises customers. The vulnerability, previously recorded as CVE-2026-18556, was thought to be resolved in version 2026.2. However, a new exploitation path was discovered, leading to the reclassification and expansion of affected versions.

The Finnish national cybersecurity center corroborated the vulnerability of all versions before the emergency patch. N-able has released a list of six IP addresses associated with the attacks, which Huntress later identified as VPN exit nodes.

Huntress has also identified domain names used by attackers and highlighted the need for customers to review logs for unauthorized access indications. The firm noted that, in one instance, attackers accessed multiple organizations under a single partner account, though the activity appeared limited to process enumeration.

N-able has yet to disclose the full scope of affected customers or data compromised. The ongoing investigation aims to clarify these details and prevent further security breaches.

The Hacker News Tags:authentication bypass, Cloudflare, CVE-2026-18577, Cybersecurity, endpoint security, Huntress, IT security, Mullvad VPN, N-able, N-central, NordVPN, remote access, Take Control, Vulnerability

Post navigation

Previous Post: SabPaisa Enhances Security with AccuKnox’s AI Cloud Technology
Next Post: MacSync Malware Targets Mac Users with Fake Guide

Related Posts

New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains The Hacker News
North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign North Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign The Hacker News
Exploitation of TrueConf Flaw Targets Southeast Asian Governments Exploitation of TrueConf Flaw Targets Southeast Asian Governments The Hacker News
CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems The Hacker News
New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site The Hacker News
AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories AI Malware, Voice Bot Flaws, Crypto Laundering, IoT Attacks — and 20 More Stories The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • N-able Releases Patch for Exploited N-central Vulnerability
  • AI’s Role in Modern Security Operations Explained
  • Coldcard Wallet Flaw Leads to Major Bitcoin Heist
  • SonicWall Vulnerabilities Exploited in Ransomware Surge
  • Chinese Threat Actor Utilizes Leaked DarkSword for iOS Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark