CVE-2026-18577
N-central Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for a prior vulnerability, CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication controls and take over user accounts, including administrative accounts, on affected N-central instances. All N-central versions through 2026.3.1 are affected; version 2026.3.1.7 is listed as unaffected. The vulnerability was disclosed on August 2, 2026, and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 score of 8.2 (High) (NVD, GitHub Advisory, CISA KEV).

Dettagli tecnici

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the patch applied for CVE-2026-18556 closed one authentication path but left an alternate path or channel unprotected, allowing attackers to circumvent authentication entirely. Exploitation requires no privileges, no user interaction, and is conducted over the network, though attack complexity is rated High, suggesting some precondition or non-trivial technique is involved (e.g., specific request crafting or timing). The vulnerability enables full account takeover of N-central administrative accounts without valid credentials. Horizon3.ai published technical research covering both CVE-2026-18556 and CVE-2026-18577, and Rapid7 published an exploitation-in-the-wild analysis (Rapid7 ETR, Horizon3.ai).

Impatto

Successful exploitation grants an unauthenticated attacker full administrative control over the N-central Remote Monitoring and Management (RMM) console — colloquially described as "god mode" access — enabling them to manage, deploy software to, and execute commands on all endpoints managed by the affected N-central server. Because N-central is used by Managed Service Providers (MSPs) to manage customer networks, a single compromised N-central instance can serve as a launchpad for supply-chain-style attacks against all downstream managed endpoints. Confirmed post-exploitation activity includes deployment of RMM tunneling tools, credential theft via Mimikatz, and ransomware deployment (StormEncryptor) across managed customer environments (BleepingComputer, The Register, Sophos).

Sfruttabilità

CVE-2026-18577 is actively exploited in the wild and was added to CISA's KEV catalog on August 3, 2026, with a federal agency remediation deadline of August 6, 2026 (CISA KEV). The China-linked threat actor Storm-1175 (a former Medusa ransomware affiliate) has been attributed to exploitation of this vulnerability, deploying the new StormEncryptor ransomware against MSP targets (The Hacker News, BleepingComputer). A GitHub repository (HORKimhab/CVE-2026-18577) exists but contains only boilerplate placeholder content with no functional exploit code; however, real-world exploitation is confirmed by multiple vendors and threat intelligence sources. The EPSS score is approximately 4.1%, and CISA's SSVC assessment rates exploitation as active, automatable, and of total technical impact (GitHub Advisory, NVD). Mullvad VPN exit nodes were reportedly observed in exploitation traffic (CybersecurityBoard).

Passaggi di sfruttamento

  1. Reconnaissance: Identify internet-facing N-central RMM servers using tools like Shodan or Censys, targeting instances running versions at or below 2026.3.1. N-central typically exposes a web management interface on standard HTTPS ports.
  2. Identify alternate authentication path: Leverage knowledge of the incomplete patch for CVE-2026-18556 to identify an alternate authentication endpoint or channel that was not covered by the original fix (CWE-288). This may involve probing authentication-adjacent endpoints or API routes that bypass the patched code path.
  3. Craft bypass request: Send a specially crafted HTTP request to the unprotected alternate authentication path, exploiting the missing authentication check to obtain a valid session or administrative token without supplying valid credentials.
  4. Achieve administrative account takeover: Use the obtained session to access the N-central administrative console with full privileges, enabling management of all connected MSP customer endpoints.
  5. Lateral movement to managed endpoints: Deploy RMM tunneling agents or remote access tools (e.g., legitimate RMM software) to managed customer endpoints via N-central's built-in software deployment capabilities, establishing persistence even if N-central server access is later revoked.
  6. Post-exploitation: Execute credential harvesting (e.g., Mimikatz), exfiltrate data, and/or deploy ransomware (StormEncryptor) across managed customer environments (BleepingComputer, Sophos, Rapid7 ETR).

Indicatori di compromesso

  • Network: Unusual or unauthenticated HTTP/HTTPS requests to N-central authentication endpoints or alternate API paths from unexpected source IPs; outbound connections from the N-central server to unknown external IPs; Mullvad VPN exit node IPs observed in access logs during exploitation (CybersecurityBoard).
  • Logs: N-central access logs showing successful administrative sessions with no corresponding valid login credentials; unexpected account creation or privilege escalation events in N-central audit logs; authentication events from unusual geographic locations or IP ranges.
  • File System: Unexpected RMM agent installers or tunneling tool binaries deployed to managed endpoints via N-central; StormEncryptor ransomware binaries (.stormenc or similar extensions on encrypted files); Mimikatz or credential dumping tool artifacts on compromised systems.
  • Process: Unusual processes spawned by the N-central service account; RMM tools (e.g., ScreenConnect, AnyDesk) installed on endpoints without change management records; credential dumping activity (lsass memory access) on managed endpoints.
  • Persistence: New scheduled tasks or services on managed endpoints installed via N-central deployment; attacker-controlled RMM agents persisting after N-central server access is revoked (Sophos, GitHub IOC Triage).

Mitigazione e soluzioni alternative

N-able released Hotfix 1 (version 2026.3.1.7) on August 2, 2026, and subsequently released Hotfix 2 on August 6, 2026, as attackers continued to exploit the vulnerability despite the first patch. Hotfix 2 supersedes Hotfix 1 and should be applied immediately. CISA mandated federal agencies apply mitigations by August 6, 2026 under BOD 26-04. Organizations should: (1) apply N-central Hotfix 2 (2026.3.1.10 or later) immediately; (2) review N-central audit logs for signs of unauthorized access; (3) audit all managed endpoints for unauthorized RMM agent installations or other persistence mechanisms; (4) restrict N-central management interface access to trusted IP ranges where possible (N-able Status HF1, N-able Status HF2, N-able Blog, CISA KEV).

Reazioni della comunità

N-able confirmed that attackers successfully reached managed customer endpoints via the vulnerability, acknowledging real-world impact in a vendor statement covered by The Register (The Register). The security community widely characterized the flaw as granting "god mode" access to MSP infrastructure, with ThreatLocker, Arctic Wolf, Rapid7, Beazley Security Labs, and eSentire all publishing advisories or technical analyses. Microsoft attributed exploitation to Storm-1175, a China-linked threat actor and former Medusa ransomware affiliate, which deployed the new StormEncryptor ransomware via compromised N-central instances (The Hacker News). Reddit communities (r/Nable, r/msp, r/sysadmin) saw significant discussion from MSP operators urgently seeking guidance, and analyst price targets for N-able (NYSE: NABL) were reportedly reduced following the incident (SimplyWallSt).

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato N-central Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-86218CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Sep 06, 2026
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 01, 2026
CVE-2026-86207HIGH7.7
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoSep 05, 2026
CVE-2026-86206MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoSep 05, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità