N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
AI Summary
Attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-able's N-central remote monitoring and management platform to gain remote administrative access to customer servers. The initial fix for CVE-2026-18556 was incomplete, allowing attackers to exploit an alternate path, later tracked as CVE-2026-18577, affecting N-central builds prior to 2026.3.1.7. After compromising N-central servers, attackers used Take Control for lateral movement and deployed Cloudflare tunnels as persistent services on managed endpoints, enabling remote access without inbound firewall rules. N-able identified six malicious IP addresses used in the attacks, and Huntress observed exploitation at one partner account, leading to access across nine downstream organizations. Post-compromise activity included process enumeration, but no data exfiltration was confirmed. Customers are advised to upgrade to build 2026.3.1.7 and hunt for malicious indicators such as suspicious svchost.exe instances and Cloudflared services.
AI-extracted · verify before operational use
Indicators of Compromise 10 extracted
| Type | Value | Detail |
|---|---|---|
| IP | 173[.]249[.]252[.]200 | Details → |
| IP | 87[.]249[.]138[.]34 | Details → |
| IP | 37[.]19[.]210[.]32 | Details → |
| IP | 37[.]153[.]90[.]88 | Details → |
| IP | 92[.]118[.]112[.]181 | Details → |
| IP | 68[.]235[.]46[.]214 | Details → |
| Domain | mousears[.]synology[.]me | Details → |
| Domain | wagoosh[.]direct[.]quickconnect[.]to | Details → |
| Domain | who-ripped-one[.]direct[.]quickconnect[.]to | Details → |
| Filename | svchost.exe | Details → |