N-able выпустила уже два патча для уязвимости обхода аутентификации в N-central
N-able has released a second emergency update for its N-central platform after confirming that threat actors are actively exploiting the zero-day flaw identified as CVE-2026-18577. This authentication bypass allows unauthorized users to seize administrative privileges on affected servers, with the vulnerability stemming from an improper fix for CVE-2026-18556.
Following detection of suspicious activity in late July 2026, CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog. The initial patch in version 2026.3.1.7 was insufficient, prompting the vendor to issue version 2026.3.1.10 which includes additional mitigations required even for systems already patched. Reports indicate attackers leveraged the compromised access to deploy Cloudflare Tunnel services for persistent backdoor access within managed environments.