a hacker doesn't need your password anymore to own the tool that protects your whole network

CVE-2026-18577 is what happens when a patch gets patched — China-linked Storm-1175 found a bypass for an already-fixed N-able N-central bug and used…

Aliteq
Priya Nair · Software & Systems Editor

The short version

CVE-2026-18577 gives an unauthenticated attacker full administrative control of an N-central server — no credentials, no MFA prompt, nothing to bypass because there's no login step to bypass.

The short version

It's assessed as a patch bypass for CVE-2026-18556, an earlier N-central auth-bypass bug — meaning the first fix didn't fully close the hole.

The short version

Storm-1175, a financially motivated China-linked actor, began deploying a new custom ransomware called StormEncryptor on August 2, 2026 — a departure from their prior reliance on rented Medusa…

The short version

N-able shipped emergency hotfixes on August 2 and again on August 6, the second one specifically closing the bypass attackers found for the first.

The short version

Security firm Huntress found more than half of internet-reachable N-central cloud servers were still unpatched after both hotfixes shipped.

The part that should worry MSPs specifically

My honest read: the fact that N-able needed a second hotfix, on August 6, to close a bypass attackers found for the first one — shipped only four days earlier — tells you Storm-1175 was already…

Aliteq

Read the full story

a hacker doesn't need your password anymore to own the tool that protects your whole network

Read the full story on Aliteq