{
  "id": 272292,
  "title": "N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands",
  "url": "https://urgent.news/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-272292",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-07T15:01:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/networks/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer-networks-as-second-hotfix-lands/5284730"
  },
  "original_language": "en",
  "account": "N-able, a vendor of remote monitoring and management platforms, has confirmed that attackers have exploited a zero-day vulnerability, CVE-2026-18577, to gain administrative access to customer networks. This occurred just days after the vendor issued a first mandatory hotfix. The attackers remotely exploited vulnerable N-central servers and used the Take Control feature to connect to systems managed through N-central. They then registered a new Cloudflare Tunnel service to maintain their presence within the compromised systems. N-able is yet to disclose the exact number of affected customers, downstream systems reached, or the actions taken by the attackers after establishing persistent access. However, the vendor has released Hotfix 2, version 2026.3.1.10, mandating installation for all N-central on-premises customers, including those who had previously installed the first emergency fix. The company warns that Hotfix 2 is required, even if the earlier hotfix has been applied. The vulnerability affects N-central servers running versions prior to 2026.3.1.7, and hosted environments have already received the latest mitigations.",
  "summary": "Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again",
  "key_points": [
    "N-able confirms attackers exploited zero-day vulnerability CVE-2026-18577.",
    "Attackers gained administrative access to customer networks via N-central servers.",
    "Vendor released Hotfix 2 (version 2026.3.1.10) mandating installation."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands",
        "url": "https://urgent.news/2026/08/07/n-able-god-mode-flaw-vendor-confirms-attackers-reached-customer",
        "published": "2026-08-07T15:01:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}