Urgent.News

What's breaking now, across thousands of outlets.

Tech

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

N-able, a security vendor, has confirmed that attackers have successfully exploited a zero-day vulnerability, CVE-2026-18577, in their N-central remote monitoring and management platform. The security flaw allows an unauthenticated attacker to gain administrative access to remote servers. Following the first hotfix released on August 2, N-able has pushed out a second mandatory hotfix, Hotfix 2, version 2026.3.1.10, just days after the first.

The second update is meant to further harden the platform as they continue to monitor threat actors evolving their attack techniques. The affected N-central servers are those running versions prior to 2026.3.1.7, and the exploitation was first detected by N-able's Adlumin managed detection and response service on July 31. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, providing U.S. federal agencies a three-day deadline to address the issue.

N-able has identified ten IP addresses associated with the attacks and released a service template for customers to detect indicators of compromise on Windows endpoints. Despite the disclosure, the vendor is warning customers to not rely solely on clean scans as an all-clear, as additional indicators may emerge as they continue their investigation.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

Meta Ordered to Pay $942 Million in New Mexico Child-Safety Lawsuit

Meghan Bobrowsky and Erin Mulvaney, reporting for The Wall Street Journal (gift link): A New Mexico judge ordered Meta Platforms to pay more than $900 million and limit the time young people in the state can spend on its apps, significantly increasing the cost of the landmark child safety verdict against the Facebook and Instagram parent.

More from Friday 7 August →