Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
N-central Servers Breached: Authentication Flaw Exploited

N-central Servers Breached: Authentication Flaw Exploited

Posted on August 3, 2026 By CWS

N-able has confirmed a breach of its N-central servers after attackers exploited an authentication bypass vulnerability, allowing them unauthorized remote administrative access. This incident, which impacts customer systems managed by these servers, underscores significant security concerns for users of the N-central platform.

Flaw Exploitation and Response

The vulnerability, identified as CVE-2026-18577, affects N-central builds prior to version 2026.3.1.7. N-able released this secure build on August 2, following the realization that their initial fix was insufficient. This platform, widely used by managed service providers and IT teams, is crucial for administering customer endpoints remotely.

Compromised servers enabled attackers to deploy ‘Take Control’ for access to managed endpoints, registering Cloudflare tunnels as services on the devices. These tunnels require no inbound firewall rules, thereby maintaining persistent access even after the initial server route is revoked.

Security Measures and Recommendations

N-able advises all N-central users to upgrade to version 2026.3.1.7 immediately. The previously recommended upgrade to version 2026.3 is now deemed inadequate. Hosted NCOD instances will receive automatic updates, while self-hosted servers need manual upgrades by customers.

In cases of suspected compromise, N-able recommends a thorough search and removal of malicious tunnel services from affected endpoints. Simply upgrading the N-central server is insufficient to clear these persistent threats.

Investigation and Ongoing Concerns

Investigations began on July 31, prompted by unusual licensing errors reported by on-premises customers. The vulnerability, previously recorded as CVE-2026-18556, was thought to be resolved in version 2026.2. However, a new exploitation path was discovered, leading to the reclassification and expansion of affected versions.

The Finnish national cybersecurity center corroborated the vulnerability of all versions before the emergency patch. N-able has released a list of six IP addresses associated with the attacks, which Huntress later identified as VPN exit nodes.

Huntress has also identified domain names used by attackers and highlighted the need for customers to review logs for unauthorized access indications. The firm noted that, in one instance, attackers accessed multiple organizations under a single partner account, though the activity appeared limited to process enumeration.

N-able has yet to disclose the full scope of affected customers or data compromised. The ongoing investigation aims to clarify these details and prevent further security breaches.

The Hacker News Tags:authentication bypass, Cloudflare, CVE-2026-18577, Cybersecurity, endpoint security, Huntress, IT security, Mullvad VPN, N-able, N-central, NordVPN, remote access, Take Control, Vulnerability

Post navigation

Previous Post: SabPaisa Enhances Security with AccuKnox’s AI Cloud Technology
Next Post: MacSync Malware Targets Mac Users with Fake Guide

Related Posts

Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord Fake Gaming and AI Firms Push Malware on Cryptocurrency Users via Telegram and Discord The Hacker News
Supply Chain Attacks Surge Amid New Malware Techniques Supply Chain Attacks Surge Amid New Malware Techniques The Hacker News
Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability Google Issues Security Fix for Actively Exploited Chrome V8 Zero-Day Vulnerability The Hacker News
New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory New MongoDB Flaw Lets Unauthenticated Attackers Read Uninitialized Memory The Hacker News
64% of 3rd-Party Applications Access Sensitive Data Without Justification 64% of 3rd-Party Applications Access Sensitive Data Without Justification The Hacker News
Enterprise Security Gaps: Insights from 25 Million Alerts Enterprise Security Gaps: Insights from 25 Million Alerts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Atlassian Rovo Vulnerable to Data Exfiltration Risks
  • Critical Metabase Flaw Exploited, Urgent Patch Released
  • OpenAI Delays Astra AI Model to Address Cybersecurity Risks
  • UNC6671 Cyber Threat Intensifies with Vishing Attacks
  • ChainDrop Worm Targets npm Packages for Credential Theft

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark