Feds get 3 days to patch N-able God mode flaw under active exploit
Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'
The US Cybersecurity and Infrastructure Security Agency (CISA) designated a recently exploited N-able vulnerability as a Known Exploited Vulnerability (KEV), mandating federal agencies to patch it within three days. This flaw, CVE-2026-18577, could enable attackers to gain full administrative access to an N-central console, a dashboard used by Managed Service Providers (MSPs) to oversee customer systems.
Attackers successfully exploited the vulnerability as of July 31, often leading to further intrusions into managed endpoints and the establishment of persistent access tunnels via Cloudflare. Huntress, a security firm, warned that exploitation could grant attackers the same level of control typically reserved for trusted Network Operations Center (NOC) and engineering staff.
They advised customers to either apply N-able's hotfix immediately or disable N-central if patching was not possible. Similar advisories were issued by other authorities, including NHS England and Belgium's Centre for Cybersecurity, emphasizing the potential for significant impact due to the vulnerability's exploitation likelihood.
This flaw is linked to a previous vulnerability, CVE-2026-18556, patched in N-central version 2026.2. Despite CISA granting a three-day deadline for Federal Civilian Executive Branch agencies to remediate the issue, nearly all cloud-hosted N-central instances were patched by August 3; however, 28.6% of self-hosted servers remained vulnerable and exposed to the internet.
Written by urgent.news from The Register's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.