Wiz가 Google Cloud에 합류: 함께 마법을 만드는 것

CVE-2026-18577
N-central 취약성 분석 및 완화

개요

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for a prior vulnerability, CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication controls and take over user accounts, including administrative accounts, on affected N-central instances. All N-central versions through 2026.3.1 are affected; version 2026.3.1.7 is listed as unaffected. The vulnerability was disclosed on August 2, 2026, and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 score of 8.2 (High) (NVD, GitHub Advisory, CISA KEV).

기술적 세부 사항

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the patch applied for CVE-2026-18556 closed one authentication path but left an alternate path or channel unprotected, allowing attackers to circumvent authentication entirely. Exploitation requires no privileges, no user interaction, and is conducted over the network, though attack complexity is rated High, suggesting some precondition or non-trivial technique is involved (e.g., specific request crafting or timing). The vulnerability enables full account takeover of N-central administrative accounts without valid credentials. Horizon3.ai published technical research covering both CVE-2026-18556 and CVE-2026-18577, and Rapid7 published an exploitation-in-the-wild analysis (Rapid7 ETR, Horizon3.ai).

영향

Successful exploitation grants an unauthenticated attacker full administrative control over the N-central Remote Monitoring and Management (RMM) console — colloquially described as "god mode" access — enabling them to manage, deploy software to, and execute commands on all endpoints managed by the affected N-central server. Because N-central is used by Managed Service Providers (MSPs) to manage customer networks, a single compromised N-central instance can serve as a launchpad for supply-chain-style attacks against all downstream managed endpoints. Confirmed post-exploitation activity includes deployment of RMM tunneling tools, credential theft via Mimikatz, and ransomware deployment (StormEncryptor) across managed customer environments (BleepingComputer, The Register, Sophos).

악용 가능성

CVE-2026-18577 is actively exploited in the wild and was added to CISA's KEV catalog on August 3, 2026, with a federal agency remediation deadline of August 6, 2026 (CISA KEV). The China-linked threat actor Storm-1175 (a former Medusa ransomware affiliate) has been attributed to exploitation of this vulnerability, deploying the new StormEncryptor ransomware against MSP targets (The Hacker News, BleepingComputer). A GitHub repository (HORKimhab/CVE-2026-18577) exists but contains only boilerplate placeholder content with no functional exploit code; however, real-world exploitation is confirmed by multiple vendors and threat intelligence sources. The EPSS score is approximately 4.1%, and CISA's SSVC assessment rates exploitation as active, automatable, and of total technical impact (GitHub Advisory, NVD). Mullvad VPN exit nodes were reportedly observed in exploitation traffic (CybersecurityBoard).

착취 단계

  1. Reconnaissance: Identify internet-facing N-central RMM servers using tools like Shodan or Censys, targeting instances running versions at or below 2026.3.1. N-central typically exposes a web management interface on standard HTTPS ports.
  2. Identify alternate authentication path: Leverage knowledge of the incomplete patch for CVE-2026-18556 to identify an alternate authentication endpoint or channel that was not covered by the original fix (CWE-288). This may involve probing authentication-adjacent endpoints or API routes that bypass the patched code path.
  3. Craft bypass request: Send a specially crafted HTTP request to the unprotected alternate authentication path, exploiting the missing authentication check to obtain a valid session or administrative token without supplying valid credentials.
  4. Achieve administrative account takeover: Use the obtained session to access the N-central administrative console with full privileges, enabling management of all connected MSP customer endpoints.
  5. Lateral movement to managed endpoints: Deploy RMM tunneling agents or remote access tools (e.g., legitimate RMM software) to managed customer endpoints via N-central's built-in software deployment capabilities, establishing persistence even if N-central server access is later revoked.
  6. Post-exploitation: Execute credential harvesting (e.g., Mimikatz), exfiltrate data, and/or deploy ransomware (StormEncryptor) across managed customer environments (BleepingComputer, Sophos, Rapid7 ETR).

타협의 징후

  • Network: Unusual or unauthenticated HTTP/HTTPS requests to N-central authentication endpoints or alternate API paths from unexpected source IPs; outbound connections from the N-central server to unknown external IPs; Mullvad VPN exit node IPs observed in access logs during exploitation (CybersecurityBoard).
  • Logs: N-central access logs showing successful administrative sessions with no corresponding valid login credentials; unexpected account creation or privilege escalation events in N-central audit logs; authentication events from unusual geographic locations or IP ranges.
  • File System: Unexpected RMM agent installers or tunneling tool binaries deployed to managed endpoints via N-central; StormEncryptor ransomware binaries (.stormenc or similar extensions on encrypted files); Mimikatz or credential dumping tool artifacts on compromised systems.
  • Process: Unusual processes spawned by the N-central service account; RMM tools (e.g., ScreenConnect, AnyDesk) installed on endpoints without change management records; credential dumping activity (lsass memory access) on managed endpoints.
  • Persistence: New scheduled tasks or services on managed endpoints installed via N-central deployment; attacker-controlled RMM agents persisting after N-central server access is revoked (Sophos, GitHub IOC Triage).

완화 및 해결 방법

N-able released Hotfix 1 (version 2026.3.1.7) on August 2, 2026, and subsequently released Hotfix 2 on August 6, 2026, as attackers continued to exploit the vulnerability despite the first patch. Hotfix 2 supersedes Hotfix 1 and should be applied immediately. CISA mandated federal agencies apply mitigations by August 6, 2026 under BOD 26-04. Organizations should: (1) apply N-central Hotfix 2 (2026.3.1.10 or later) immediately; (2) review N-central audit logs for signs of unauthorized access; (3) audit all managed endpoints for unauthorized RMM agent installations or other persistence mechanisms; (4) restrict N-central management interface access to trusted IP ranges where possible (N-able Status HF1, N-able Status HF2, N-able Blog, CISA KEV).

커뮤니티 반응

N-able confirmed that attackers successfully reached managed customer endpoints via the vulnerability, acknowledging real-world impact in a vendor statement covered by The Register (The Register). The security community widely characterized the flaw as granting "god mode" access to MSP infrastructure, with ThreatLocker, Arctic Wolf, Rapid7, Beazley Security Labs, and eSentire all publishing advisories or technical analyses. Microsoft attributed exploitation to Storm-1175, a China-linked threat actor and former Medusa ransomware affiliate, which deployed the new StormEncryptor ransomware via compromised N-central instances (The Hacker News). Reddit communities (r/Nable, r/msp, r/sysadmin) saw significant discussion from MSP operators urgently seeking guidance, and analyst price targets for N-able (NYSE: NABL) were reportedly reduced following the incident (SimplyWallSt).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 N-central 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2026-86218CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Sep 06, 2026
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 01, 2026
CVE-2026-86207HIGH7.7
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
아니요Sep 05, 2026
CVE-2026-86206MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
아니요Sep 05, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자