ALITEQ.

a hacker doesn't need your password anymore to own the tool that protects your whole network

CVE-2026-18577 is what happens when a patch gets patched — China-linked Storm-1175 found a bypass for an already-fixed N-able N-central bug and used it to skip straight to full admin access, no login required.

Priya NairUpdated 2h ago6 min readWeb story
IT administrator monitoring network servers on a control room screen

N-able N-central is remote-monitoring software that managed service providers use to reach into and administer their clients' networks — one login, hundreds of businesses. That's exactly why CVE-2026-18577 is such a bad bug: it's an authentication bypass, tracked by researchers as a bypass for the patch that was supposed to fix a previous authentication bypass, and a China-linked group called Storm-1175 has already used it to deploy a brand-new ransomware strain against N-central customers.

What "god-mode access" actually means here

There's no clever social engineering step in this attack, and that's the point. Reporting on CVE-2026-18577 describes it as unauthenticated "god-mode" access — an attacker can reach an N-central server over the network and act with full administrative privileges immediately, with nothing to steal, phish, or brute-force first. For a normal piece of software that's bad. For an RMM platform, whose entire job is to remotely execute commands on other companies' machines, it's close to the worst possible bug: the attacker inherits the same reach the MSP itself has.

The bug that got re-broken

CVE-2026-18556

CVE
Original N-central authentication bypass / account takeover

CVE-2026-18577

CVE
Bypass for N-able's fix to CVE-2026-18556 — same outcome, different path
Computer screen displaying a ransomware ransom note warning
StormEncryptor drops a note named !!!README_FIRST!!!.txt into every directory it touches, after appending .encrypted to the files inside. · Unsplash

Why RMM software is ransomware's favorite force multiplier

This isn't a new playbook, even if the specific bug is new. Remote-monitoring-and-management tools exist to let one operator touch many networks at once — that's the sales pitch. It's also the attack surface. Break into the RMM layer and you don't need to individually compromise each downstream client; the software was already built to let you reach all of them, with the kind of trusted, expected-looking network access that most detection tooling waves through. Industry incident history keeps circling back to this same shape: compromise the tool built for scale, and the blast radius scales with it.

Reporting on the intrusion describes the speed as the standout detail — Storm-1175 collapses initial access to full ransomware deployment into a window short enough that many victim organizations reportedly only realize they've been hit once files are already encrypted and the ransom note is sitting in every folder. That's not a slow, patient nation-state operation. It's a financially motivated crew that has clearly automated the boring parts.

Confirm your N-central instance has the August 6, 2026 hotfix applied — not just the August 2 one, which the attackers bypassed.

Audit N-central admin logs for any unrecognized administrative sessions or configuration changes since early August.

Watch downstream client endpoints for the IOC pattern: files renamed with a .encrypted extension and a ransom note called !!!README_FIRST!!!.txt.

If you find signs of compromise, assume every client network the N-central instance had reach into needs its own incident review — not just the RMM server itself.

Segment N-central's management access from the general internet where your deployment model allows it; "god-mode with no login" is a much smaller problem behind a VPN or allowlist.

Aug 6, 2026

Second hotfix

Fixes bypass of the Aug 2 patch

Over half

Unpatched servers

Of internet-reachable N-central cloud instances, per Huntress

Medusa → StormEncryptor

Ransomware tool switch

Storm-1175 now builds custom malware instead of renting it

The tool-switch detail matters more than it might look. Renting a ransomware-as-a-service kit like Medusa is what a group does when it's still scaling up — it's faster to deploy but it means sharing profit and infrastructure with an affiliate program. Building your own encryptor, as Storm-1175 has now done with StormEncryptor, is what a group does once it has the resources and the confidence to run the whole operation itself. That's a maturity signal, not just a name change, and it lines up with a pattern we've tracked all year: groups that started as MFA-bypassing opportunists exploiting Fortinet VDI flaws or riding static-credential zero-days in Cisco's firewall manager are graduating into groups that write their own tooling and pick their own targets.

Quick questions

Do I need to have been already breached by CVE-2026-18556 to be at risk from CVE-2026-18577?
No. CVE-2026-18577 is a separate exploitable path that achieves the same unauthenticated access, even on servers where the original CVE-2026-18556 was already patched.
Is StormEncryptor targeting a specific industry?
Reporting hasn't identified a single targeted sector — the attack vector is the shared N-central platform, which MSPs use across every industry they serve, so the exposure follows wherever N-central is deployed rather than any one vertical.
How do I know if my organization uses N-central even indirectly?
If you outsource IT management to a third-party MSP, ask them directly whether N-able N-central is part of their toolset and whether both August hotfixes are confirmed applied — you may be exposed without ever having heard of the software.
Is this connected to the SharePoint or Defender bypass stories from earlier this month?
No — different vendor, different vulnerability class, different threat actor. It's part of the same broader August 2026 wave of authentication-bypass bugs turning into fast ransomware deployment, not the same campaign.

If you run or rely on an MSP, this week's homework is one phone call: ask whether N-central is patched to the August 6 build, not the August 2 one. That's the entire difference between closed and still-open.

Software & Systems Editor

Priya Nair

Priya has daily-driven more Linux distros than she can name and treats her setup like a workshop. She covers the operating systems, apps and settings worth your time — and cheerfully calls out the 'optimizations' that just quietly break your machine.

Work out the hardware

The Aliteq brief

The tech worth knowing — hardware, AI, gaming, deals. No spam, unsubscribe anytime.

Keep reading