N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

https://image.theregister.com/5284672.jpg?imageId=5284672&x=0&y=18.23&cropw=100&croph=63.55&panox=0&panoy=18.23&panow=100&panoh=63.55&width=1200&height=683

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

N-able has confirmed attackers exploiting an N-central zero-day made it into customer networks, as the vendor pushes out a second mandatory hotfix just days after the first.

The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform.

According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them.

Once there, they registered a new Cloudflare Tunnel service to keep their foothold even after being booted from the N-central server – behavior that Huntress had already observed in the wild.

N-able has now confirmed that its own investigation found the same activity, and...

Copyright of this story solely belongs to theregister.com. To see the full text click HERE

Read more