Tag: n central
8 articles

N-able Patches Remote Code Execution Flaw in N-central Platform
A critical vulnerability, CVE-2026-86218, was discovered in N-able's N-central platform, allowing unauthenticated attackers to execute code on the server - and a patch is now available in N-central 2026.3 Hotfix 4. Update now to prevent potential remote code execution attacks!

N-able Rushes Fourth Hotfix for Unauthenticated RCE Flaw in N-central
N-able has urgently released a fourth hotfix in just five weeks to tackle a critical, unauthenticated remote code execution flaw in its N-central software, affecting all on-premises builds prior to version 2026.3.1.14. All users of these outdated versions must apply the latest fix to safeguard against this maximum-severity vulnerability.

N-able Rushes Patch for Max-Severity RCE Flaw Under Attack
N-able has urgently released a hotfix to tackle a critical remote code execution flaw in its N-central platform, warning customers to patch immediately to protect their environment from potential attacks. With nearly 1,500 N-central servers exposed online, mainly in the US and Europe, swift action is crucial to prevent exploitation.

China-Linked Hackers Deploy StormEncryptor Ransomware via N-central Flaw
Meet StormEncryptor, a sneaky new ransomware strain linked to China that's leaving a trail of encrypted files and ransom notes in its wake. This malicious software, written in C++, is marked by its telltale .encrypted file extension and !!!README_FIRST!!!.txt ransom notes.

CISA Warns of Active Exploits in Langflow, N-central, Apache Tomcat Flaws
A critical flaw in IBM's Langflow, rated 9.8 out of 10, allows hackers to remotely execute code on vulnerable systems - and multiple easy-to-follow exploits have already surfaced online. This severe vulnerability enables attackers to bypass login and wreak havoc, making it a pressing concern for Langflow users.

CISA Warns of Active Exploits Targeting Langflow, Tomcat, and N-central Flaws
Stay safe online: CISA has flagged three major cybersecurity vulnerabilities, including a critical remote code execution flaw in Langflow, that are being actively exploited by hackers. A patch is available for the Langflow flaw, which was fixed in version 1.10.1.

N-able Discloses Auth Bypass Flaw in N-central Exploited in Attacks
A critical authentication bypass vulnerability, CVE-2026-18577, is under active attack, putting N-able's N-central servers at risk - but a hotfix (2026.3.1.7) is now available to prevent further exploitation. This flaw is linked to an earlier, incomplete patch for CVE-2026-18576, which also threatened administrative account takeovers.

N-able Servers Compromised After Incomplete Fix
N-able's servers were compromised due to an incomplete fix for a critical vulnerability, allowing attackers to exploit an authentication bypass and gain remote administrative access to on-premises servers and customer systems. The incident highlights the importance of thorough patching, as N-able's initial fix failed to fully address the issue.