Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
4 / 6 results
criticalbug_reportVulnerabilityN-able N-central exploited; attackers persist via Cloudflare tunnels
N-able N-central RMM product, all versions prior to 2026.3.1.7. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both enabling authentication bypass and account takeover. On-premise deployments are affected.
highbug_reportVulnerabilityN-able N-central auth bypass exploited; CISA orders patch by Aug 6
N-able N-central versions prior to 2026.3 HF1. CVE-2026-18577 (CVSS 8.2) is an incomplete patch for CVE-2026-18556. Affects on-premises N-central servers with remote management capabilities.
highbug_reportVulnerabilityN-able N-central auth bypass exploited; affects all pre-2026.3 versions
N-able N-central RMM platform, all versions prior to 2026.3. Affects both hosted and on-premises deployments. Hosted instances patched automatically; on-premises require manual hotfix 2026.3.1.7 installation.
criticalbug_reportVulnerabilityN-able N-central auth bypass exploited; incomplete patch requires upgrade
N-able N-central builds prior to 2026.3.1.7. All versions before the August 2 emergency hotfix are vulnerable. Affects MSPs and IT teams using N-central for remote monitoring and management of customer endpoints.