All CosmicBytez Labs articles tagged #N-able, across news, security advisories, how-to guides, and projects.
Microsoft tracks Storm-1175 pivoting from Medusa ransomware to a new strain — StormEncryptor — exploiting an N-able N-central authentication bypass that puts thousands of MSPs and their downstream clients at risk.
Microsoft warns that the China-linked threat actor Storm-1175 is exploiting a critical zero-day in N-able N-central (CVE-2026-18577) to gain god-mode access to MSP platforms and deploy the custom StormEncryptor ransomware across thousands of downstream client networks.
N-able has released a mandatory second hotfix for N-central after attackers exploiting CVE-2026-18556 and CVE-2026-18577 pivoted through Take Control to managed endpoints and deployed persistent Cloudflare tunnels — footholds that survive patching N-central itself.
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 5, 2026 — a critical Langflow RCE, an Apache Tomcat encryption flaw, and an N-able N-central authentication bypass — all confirmed under active exploitation with a federal patch deadline of August 7.
N-able N-central contains an authentication bypass via alternate path vulnerability enabling full account takeover, added to CISA KEV as an incomplete patch for CVE-2026-18556.