N-able N-central – God Mode on the Management Plane, and the Hotfix That Wasn't Enough
Tech Talks With Kinsoft di Steven Kinnas
Note sull'episodio
At the start of August 2026, attackers exploited an authentication bypass in N-able's N-central remote monitoring and management platform to obtain full administrative control of the console - and then used the product's own legitimate remote access feature to reach the machines it manages. The vendor shipped a fix. It was not enough.
The six-day timeline. 1 Aug: N-able detects active exploitation of CVE-2026-18556 (CVSS 7.4 under v3.1, 8.2 under v4.0); all versions affected, hosted and on-premises. 2 Aug: hotfix 1, build 2026.3.1.7, plus a second advisory for CVE-2026-18577 - the residual bypass left by the incomplete fix (8.1 under v3.1, 8.2 under v4.0). 3 Aug: CISA adds 18577 to the Known Exploited Vulnerabilities catalogue. 4 Aug: CISA adds 18556; N-able confirms attackers obtained administrative access. 6 Aug: hotfix 2, build 2026.3.1. ...