View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

N-central Zero-Day Let Attackers Control Servers and Managed Devices

๐Ÿšจ ACTIVE EXPLOITATION

  • N-central Zero-Day Let Attackers Control Servers and Managed Devices CVE-2026-18577 Attackers exploited a zero-day in N-able N-central to gain administrative access.

    • N-able N-central customers using hosted or on-premises deployments were affected.
    • CVE-2026-18577 affected N-central versions through 2026.3.1 and enabled unauthenticated administrative access.
    • Attackers abused N-central Take Control to reach domain controllers, backup servers, and application servers.
    • Threat actors deployed AnyDesk, TacticalRMM, TeamViewer, RustDesk, SimpleHelp, HopToDesk, and Cloudflare tunnels for persistent access.
    • Observed indicators included renamed cloudflared files such as MicrosoftEdgeUpdate64.exe or msmp.exe, plus IPs 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, and 68.235.46.214. ๐Ÿ“„ Source: n-able.com ยท ๐Ÿ“Ž Coverage: sophos.com ยท ๐Ÿ‘ via @GossiTheDog@cyberplace.social
  • UPDATE: SMOKE#SCREEN campaign uses fake updates to deploy ScreenConnect RMM SMOKE#SCREEN attackers are using fake software updates to install ScreenConnect for persistent remote access.

    • Windows and macOS users are targeted with fake Zoom, Adobe, document-review, and system-maintenance lures.
    • The campaign silently installs legitimate ConnectWise ScreenConnect agents, giving attackers persistent remote desktop access.
    • Spear-phishing delivers VBScript droppers, batch loaders, .NET executables, or HTML phishing pages.
    • Cloudflare Quick Tunnels and a WsgiDAV staging server at 207.174.0[.]143:8080 deliver payloads and support relay traffic.
    • ScreenConnect relays include 207.174.0[.]143:8041, 142.202.191.225:8041/80, and blog.derrspecial-onlinedmin.live:8041. ๐Ÿ“„ Source: securonix.com ยท ๐Ÿ“Ž Coverage: thehackernews.com ยท ๐Ÿ‘ via @GossiTheDog@cyberplace.social

๐Ÿ”“ CVEs & KEV

  • CVE-2026-56162 โ€” CVSS 10.0 โ€” Azure SQL Database Elevation of Privilege VulnerabilityImproper authenticatio...
  • CVE-2026-65667 โ€” CVSS 10.0 โ€” Microsoft Teams Elevation of Privilege VulnerabilityMissing authorization in ...
  • CVE-2026-50515 โ€” CVSS 9.9 โ€” Azure Service Bus Remote Code Execution VulnerabilityDeserialization of untru...
  • CVE-2026-59115 โ€” CVSS 9.9 โ€” Microsoft Entra Provisioning Service Elevation of Privilege Vulnerability'......
  • CVE-2026-50481 โ€” CVSS 9.9 โ€” Azure Active Directory Elevation of Privilege VulnerabilityModification of as...
  • CVE-2026-62873 โ€” CVSS 9.8 โ€” Microsoft 365 Admin Center Elevation of Privilege VulnerabilityImproper verif...
  • CVE-2026-70332 โ€” CVSS 9.6 โ€” Microsoft Office SharePoint Spoofing VulnerabilityServer-side request forgery...
  • CVE-2026-62896 โ€” CVSS 9.6 โ€” Microsoft Teams Elevation of Privilege VulnerabilityImproper authentication i...
  • CVE-2026-59118 โ€” CVSS 9.3 โ€” Microsoft Power Apps Elevation of Privilege VulnerabilityImproper authorizati...
  • CVE-2026-68823 โ€” CVSS 9.1 โ€” Azure Confidential Ledger Remote Code Execution VulnerabilityExposed dangerou...
  • CVE-2026-49163 โ€” CVSS 8.8 โ€” Application Insights Profiler Elevation of Privilege VulnerabilityImproper li...
  • CVE-2026-62836 โ€” CVSS 8.7 โ€” Azure SQL Managed Instance Elevation of Privilege VulnerabilityImproper restr...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check