Feds get 3 days to patch N-able God mode flaw under active exploit

← Back to the feed

Feds get 3 days to patch N-able God mode flaw under active exploit

The Register · 4 hours ago

The US Cybersecurity and Infrastructure Security Agency (CISA) has added an actively exploited N-able vulnerability to its Known Exploited Vulnerabilities catalogue, giving federal agencies just three days to patch it. The flaw, tracked as CVE-2026-18577, affects N-central, a platform widely used by managed service providers (MSPs) to administer customer systems from a single dashboard, meaning successful exploitation could expose numerous downstream organisations rather than a single victim.

Security firm Huntress said attackers exploiting the bug gain "full administrative access to an N-central console" — control normally reserved for trusted network operations and engineering staff — allowing them to open remote sessions on critical systems, alter accounts and policies, pivot into managed endpoints, and set up Cloudflare tunnels for persistent access. The vulnerability, rated 8.2 on CVSSv4, affects N-central versions before 2026.3 when servers are internet-facing, and stems from an incomplete fix for an earlier flaw, CVE-2026-18556. CISA has set an August 6 deadline for US federal agencies under its Binding Operational Directive, while NHS England and Belgium's cybersecurity centre have also urged urgent patching; by August 3, Huntress found nearly all cloud-hosted instances patched, though 28.6 per cent of self-hosted, internet-exposed servers remained vulnerable.

  • CISA gives US agencies three days to patch exploited N-able flaw
  • Bug grants attackers full admin access to N-central consoles
  • 28.6% of exposed self-hosted servers still unpatched as of 3 August

Software

Read the full article at the source →