N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again..

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again.
The short version
- The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform.
- According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them.
- Once there, they registered a new Cloudflare Tunnel service to keep their foothold even after being booted from the N-central server – behavior that Huntress had already observed in the wild .
What happened
N-able has now confirmed that its own investigation found the same activity, and says a "limited number" of customers were affected. For NNN readers, the useful bit is how n-able god mode flaw: vendor confirms attackers reached customer networks as second hotfix lands changes the immediate story in this beat.
Why it matters
The Register — Networks says n-able god mode flaw: vendor confirms attackers reached customer networks as second hotfix lands is the central development readers should understand.
Summary by Nerd News Network. Read the full article at The Register — Networks via the links above and below.
