Urgent.News

600+ sources. One page. See who else covered it.

Editions

Science

Feds get 3 days to patch N-able God mode flaw under active exploit

Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'

Feds get 3 days to patch N-able God mode flaw under active exploit

The US Cybersecurity and Infrastructure Security Agency (CISA) has granted federal agencies three days to remedy a critical flaw in the N-able N-central platform. The vulnerability, tracked as CVE-2026-18577, allows attackers to gain full administrative access to the console, enabling them to pivot onto managed endpoints and establish persistent tunnels for victim networks.

Tracked as a high-risk issue, CISA urged agencies to remediate the flaw by August 6, as part of Binding Operational Directive 26-04. Huntress security firm observed that nearly all cloud-hosted N-central instances had been patched by August 3, but 28.6 percent of self-hosted servers remained vulnerable.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science