INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

N-able N-central flaw exploited by Lazarus Group via spear-phishing

| 2026-08-04 11:02 CRITICAL HIGH EXPLOITED VULNERABILITY PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
The recent incident data reveals a sophisticated cyber attack targeting organizations with vulnerable N-central cloud servers. The attackers exploited the "N-able N-central flaw" (CVE-2026-18577) and gained access by conducting reconnaissance, enumerating processes, moving laterally across networks, and exploiting authentication bypass vulnerabilities. This is not an isolated incident; U.S. CISA has added this vulnerability to its Known Exploited Vulnerabilities catalog, emphasizing the need for immediate patching. Organizations are advised to upgrade their N-central software versions to 2026.3.1.7 or later by August 4th, as some customers were compromised and more than half of reachable servers remained unpatched against this vulnerability. The attackers also exploited registered Cloudflared services and inbound firewall connections from listed IP addresses, highlighting the ongoing abuse of remote monitoring and management platforms to gain persistent access.
Technical Mitigations AI-generated
* Update N-central to the latest version: Customers should immediately upgrade to a recent version of N-central (2026.3.1.7 or later) as soon as possible, especially if they have not already done so. * Patch CVE-2026-18556 first: Before applying patch for CVE-2026-18577, customers should ensure that their systems are patched against the previously exploited vulnerability tracked as CVE-2026-18556 (CVSS score: 8.2). * Use a secure RMM solution: Organizations should consider using a reputable Remote Monitoring and Management (RMM) platform to monitor for potential vulnerabilities and prevent exploitation, such as Mullvad or NordVPN. * Regularly review the Catalog: Private organizations should regularly check their infrastructure against known exploitable vulnerabilities in N-able N-central and address any identified issues before they can be exploited.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

sv•••••.exe
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2025-8876CVE-2025-8876 CVE-2026-18556CVE-2026-18556 CVE-2026-18577CVE-2026-18577 CVE-2025-8875CVE-2025-8875
Target & Sectors
Global Scope governmentgovernment
Incident Timeline
‎Aug 04, 2026
Threat actors exploited a known vulnerability in the National Vulnerability Database (NVD) catalog.
‎2026/08/04
N-able added a high-severity security flaw to its Known Exploited Vulnerabilities catalog due to reports of active exploitation in the wild, specifically CVE-2026-18577 (CVSS 8.2) an authentication bypass flaw caused by incomplete patching for CVE-2026-18556.
organisation N-Central Take Control
organisation Huntress
organisation CVE-2026
infrastructure 8.2
infrastructure 2026.3.1
organisation IP
organisation Cloudflare
infrastructure 37.19.210
organisation RMM
organisation Huntress’s
infrastructure 2026.3
organisation 87.249.138[.]34
‎August 6, 2026
The Federal Civilian Executive Branch (FCEB) agencies are being recommended to apply a known exploited vulnerability in N-central by August 6, 2026.
attribution FCEB
attribution Federal Civilian Executive Branch
Tactical Metrics
Metrics
infrastructure
‎2026.3.1
Software Version
Metrics
infrastructure
‎37.19.210
Software Version
Metrics
infrastructure
‎8.2
Software Version
Metrics
infrastructure
‎2026.3
Software Version