Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AICISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
CISA has added a high-severity vulnerability (CVE-2026-18577) affecting N-able N-central to its Known Exploited Vulnerabilities catalog after confirmed active exploitation. The flaw, with a CVSS score of 8.2, represents an incomplete patch for a previous vulnerability (CVE-2026-18556), leading to customer compromises in the wild.
AIN-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able disclosed that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in its N-central remote monitoring and management platform, allowing them to gain remote administrative access to customer systems. The company's initial fix proved incomplete, requiring a subsequent patch. N-central build 2026.3.1.7, released August 2, is the first version that fully addresses the vu
