Smart news for curious minds.

Nerd News Network
Networking

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again..

Lead image for “N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands”.
Image: The Register — Networks
Share

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again.

The short version

  • The security shop published an update on Thursday detailing what happened after attackers exploited CVE-2026-18577, the critical N-central flaw that can hand an unauthenticated attacker administrative access to the remote monitoring and management platform.
  • According to N-able, attackers exploited vulnerable N-central servers remotely, then used the platform's Take Control feature to connect to systems inside the environments being managed through them.
  • Once there, they registered a new Cloudflare Tunnel service to keep their foothold even after being booted from the N-central server – behavior that Huntress had already observed in the wild .

What happened

N-able has now confirmed that its own investigation found the same activity, and says a "limited number" of customers were affected. For NNN readers, the useful bit is how n-able god mode flaw: vendor confirms attackers reached customer networks as second hotfix lands changes the immediate story in this beat.

Why it matters

The Register — Networks says n-able god mode flaw: vendor confirms attackers reached customer networks as second hotfix lands is the central development readers should understand.

Summary by Nerd News Network. Read the full article at The Register — Networks via the links above and below.

Share