N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

2026-08-03T07:23:58Z4a1b381ad07e65be4d169a729a259159fc8f78d21cefcb54fee4c6f1e7149061
CVE-2026-18577CVE-2026-48449active-exploitationai-securityauthentication-bypassbrowser-securitybyovdcloud-data-exposurecloud-securitycryptocurrency-theftmalwaremobile-securitynetwork-securityoauth-device-code-phishingphishingprivilege-escalationransomwareremote-code-executionsession-hijackingstate-sponsoredsupply-chain-compromisezero-day

What happened

The feed reports multiple high-impact cybersecurity incidents and vulnerabilities, including actively exploited enterprise software flaws, authentication bypass and remote administrative takeover of N-able N-central, arbitrary code execution in Adobe Campaign Classic and Hugging Face Diffusers, cloud-wide data exposure in Azure Cosmos DB, Cisco FMC zero-day exploitation, telecom core session hijacking risks, supply-chain compromises, malware campaigns, phishing, BYOVD attacks, and state-sponsored activity. Several incidents involve confirmed exploitation or significant potential for remote or横

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4a1b381ad07e65be4d169a729a259159fc8f78d21cefcb54fee4c6f1e7149061
Enrichment time
2026-08-03T07:23:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.