Tag: cve 2026 18577
7 articles

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw
Meet StormEncryptor, a sneaky new ransomware strain linked to China that's leaving a trail of encrypted files and ransom notes in its wake. This malicious software, written in C++, is marked by its telltale .encrypted file extension and !!!README_FIRST!!!.txt ransom notes.

N-able Bolsters Defenses as Attackers Exploit RMM Flaw
N-able is stepping up its defenses with a second hotfix for its N-central Remote Monitoring and Management product, proactively expanding protections to stay ahead of evolving attack techniques that exploit a recently disclosed vulnerability. This latest update is a must-apply, even if you've already installed the earlier hotfix, as it includes crucial additional hardening measures to safeguard you and your customers.

N-able Flaw Exposes Customer Networks to Attackers
A critical vulnerability in N-able's N-central platform, known as CVE-2026-18577, has been exploited by attackers to gain unauthorized access to customer networks, allowing them to take control of managed endpoints. This flaw gave attackers an open door to wreak havoc, and it's essential for affected users to take immediate action to protect themselves.

CISA Warns of Active N-able Flaw Exploit in Federal Agencies
Exploiting the N-able flaw can give attackers unrestricted control over your N-central console, putting your entire operation at risk. Federal agencies have just three days to patch this high-severity vulnerability, tracked as CVE-2026-18577, under CISA's Binding Operational Directive 26-04.

CISA Flags N-able N-central Flaw as Exploited Vulnerability
A critical flaw in N-able N-central has been flagged by CISA as an exploited vulnerability, allowing attackers to bypass authentication and take over accounts. This weakness, known as CVE-2026-18577, lets hackers gain admin access to vulnerable servers and deploy malicious persistence mechanisms.

N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account takeovers.

N-able Servers Compromised After Incomplete Fix
N-able's servers were compromised due to an incomplete fix for a critical vulnerability, allowing attackers to exploit an authentication bypass and gain remote administrative access to on-premises servers and customer systems. The incident highlights the importance of thorough patching, as N-able's initial fix failed to fully address the issue.