{
  "id": 270644,
  "title": "N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands",
  "url": "https://urgent.news/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-07T15:01:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730"
  },
  "original_language": "en",
  "account": "N-able, a security vendor, has confirmed that attackers have successfully exploited a zero-day vulnerability, CVE-2026-18577, in their N-central remote monitoring and management platform. The security flaw allows an unauthenticated attacker to gain administrative access to remote servers. Following the first hotfix released on August 2, N-able has pushed out a second mandatory hotfix, Hotfix 2, version 2026.3.1.10, just days after the first. The second update is meant to further harden the platform as they continue to monitor threat actors evolving their attack techniques. The affected N-central servers are those running versions prior to 2026.3.1.7, and the exploitation was first detected by N-able's Adlumin managed detection and response service on July 31. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, providing U.S. federal agencies a three-day deadline to address the issue. N-able has identified ten IP addresses associated with the attacks and released a service template for customers to detect indicators of compromise on Windows endpoints. Despite the disclosure, the vendor is warning customers to not rely solely on clean scans as an all-clear, as additional indicators may emerge as they continue their investigation.",
  "summary": "Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again",
  "key_points": [
    "N-able confirms attackers exploited zero-day vulnerability CVE-2026-18577.",
    "Second hotfix, Hotfix 2 version 2026.3.1.10, released to harden platform.",
    "CISA added vulnerability to Known Exploited Vulnerabilities catalog."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands",
        "url": "https://urgent.news/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-272292",
        "published": "2026-08-07T15:01:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}