CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity vulnerability in N-able N-central to its KEV catalog due to active exploitation. This flaw, stemming from incomplete patching of a previous vulnerability, allows for authentication bypass and account takeover, enabling attackers to gain administrative access and deploy persistence mechanisms. Threat actors are actively targeting N-central across multiple organizations, utilizing VPN exit nodes and conducting reconnaissance to target key servers. Agencies are urged to apply the fix by August 6, 2026.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
