{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-18577/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-18577"},{"id":"CVE-2026-18556"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["N-central (\u003c 2026.3.1.7)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","rmm","cve-2026-18577","exploitation"],"_cs_type":"advisory","_cs_vendors":["N-able"],"content_html":"\u003cp\u003eN-able has identified and released patches for CVE-2026-18577, an authentication bypass vulnerability affecting N-central remote monitoring and management (RMM) software versions prior to 2026.3.1.7. This vulnerability functions as a patch bypass for the previously disclosed CVE-2026-18556. Attackers are actively exploiting this flaw in the wild to achieve full administrative access to on-premises and cloud-hosted N-central consoles. Once inside, attackers leverage the platform's legitimate 'Take Control' feature to pivot into managed environments. To maintain persistence after the initial server-level vulnerability is mitigated, actors have been observed registering new services for Cloudflare tunnels on compromised endpoints. This activity presents a critical risk to Managed Service Providers (MSPs) and their downstream clients, as attackers gain the ability to deploy scripts, run discovery utilities, and initiate remote sessions into sensitive internal systems such as domain controllers.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker exploits the authentication bypass vulnerability (CVE-2026-18577) in the internet-facing N-central console.\u003c/li\u003e\n\u003cli\u003eActor gains administrative access to the N-central console, bypassing existing authentication controls.\u003c/li\u003e\n\u003cli\u003eActor utilizes the platform's built-in 'Take Control' feature to initiate remote sessions into managed endpoints.\u003c/li\u003e\n\u003cli\u003eActor interacts with managed servers or workstations via the legitimate N-able agent to gain code execution.\u003c/li\u003e\n\u003cli\u003eActor executes discovery utilities or dual-use tools to assess the internal environment of the managed system.\u003c/li\u003e\n\u003cli\u003eActor installs and registers a new service specifically for a Cloudflare tunnel on the target endpoint.\u003c/li\u003e\n\u003cli\u003eActor establishes persistent command and control (C2) channel via the tunnel to maintain environment access.\u003c/li\u003e\n\u003cli\u003eActor proceeds with follow-on activities, such as credential harvesting or further lateral movement across the client environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants threat actors administrative control over the N-central console, providing the same level of authority as trusted NOC and engineering personnel. Attackers can push arbitrary scripts, deploy dual-use tools, initiate remote-control sessions, and modify security policies across all managed servers and workstations, including highly sensitive infrastructure like domain controllers. This poses a significant supply chain threat, as a single compromised RMM console can compromise an entire downstream customer base.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update all N-central installations to version 2026.3.1.7 or later to address CVE-2026-18577.\u003c/li\u003e\n\u003cli\u003eReview N-central environment logs for any unusual service registrations, specifically looking for new services related to Cloudflare tunnels or unexpected remote management activity.\u003c/li\u003e\n\u003cli\u003eAudit administrative access logs in N-central for unauthorized account usage or atypical login patterns.\u003c/li\u003e\n\u003cli\u003eInvestigate managed endpoints for the presence of unauthorized tunnel services or non-standard remote access tools initiated by the N-able agent.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-03T13:04:50Z","date_published":"2026-08-03T13:04:50Z","id":"https://feed.craftedsignal.io/briefs/2026-08-n-able-n-central-bypass/","summary":"Threat actors are actively exploiting a patch bypass vulnerability (CVE-2026-18577) in N-able N-central to gain administrative control and establish persistent remote access via Cloudflare tunnels.","title":"N-able N-central Authentication Bypass Exploitation","url":"https://feed.craftedsignal.io/briefs/2026-08-n-able-n-central-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-18577","version":"https://jsonfeed.org/version/1.1"}