Feds get 3 days to patch N-able God mode flaw under active exploit
Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'
The US Cybersecurity and Infrastructure Security Agency (CISA) has granted federal agencies three days to remedy a critical flaw in the N-able N-central platform. The vulnerability, tracked as CVE-2026-18577, allows attackers to gain full administrative access to the console, enabling them to pivot onto managed endpoints and establish persistent tunnels for victim networks.
Tracked as a high-risk issue, CISA urged agencies to remediate the flaw by August 6, as part of Binding Operational Directive 26-04. Huntress security firm observed that nearly all cloud-hosted N-central instances had been patched by August 3, but 28.6 percent of self-hosted servers remained vulnerable.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.