Signal Attackers Exploit N-able N-central Authentication Bypass Flaw to Reach Managed Endpoints (CVE-2026-18577)
Summary
On August 3, 2026, Help Net Security reported that attackers are actively exploiting CVE-2026-18577, an authentication bypass vulnerability affecting all N-able N-central versions prior to 2026.3.1.7, covering both on-premises and cloud-hosted deployments. The flaw is not a new zero-day but a newly discovered method to bypass the patch previously issued for CVE-2026-18556. N-able first detected an unusual spike in licensing errors among on-premises customers on July 31, 2026, and confirmed active exploitation of the bypass on August 2. The same day, N-able released hotfix version 2026.3.1.7, which was automatically applied to vendor-hosted instances. Attackers who gain admin access abuse N-central's built-in Take Control feature to reach managed endpoints, and register a new Cloudflare tunnel service to maintain persistence after losing direct server access. As of August 3, security firm Huntress found that 55.6% of partner cloud servers remained unpatched.
Classification
Evidence 1
- Help Net Security 2026-08-03 accessed 2026-08-05T02:02:05+00:00
Part of trends 0
No objects.
Directly linked issues 0
No objects.
Public id: fm-d8c1f907d280