started · updated
N-able N-central authentication bypass exploited in the wild, prompting urgent patches
A remote unauthenticated authentication bypass (CVE-2026-18577) in N-able's N-central remote‑monitoring platform has been observed in the wild since August 1, 2026. The flaw lets attackers gain administrative control of N-central servers and, using the platform’s Take Control feature, access downstream managed endpoints. Exploitation was confirmed by N-able and the vulnerability was added to the U.S. CISA Known Exploited Vulnerabilities catalog on August 3. Affected deployments include all N-central versions up to 2026.3.1 prior to Hotfix 1; remediation requires applying the hotfix or upgrading to the fixed version, reviewing logs for Cloudflare Tunnel services and suspicious svchost.exe files, and engaging incident‑response teams.
Separately, research from Lasso examined how the runtime harness that orchestrates large language model agents can dramatically alter red‑team attack outcomes. By keeping the model, prompt, tools, and targets constant and swapping only the harness—comparing Anthropic’s Claude Agent SDK with the open‑source deepagents framework built on LangGraph—the study found wide variance in success rates across the same underlying models. The findings highlight that harness selection is as critical as model choice for enterprise AI deployments, and that autonomous agents may misclassify failed attacks as successful, underscoring the need for independent validation.
Entities
Anthropic · CISA · CVE-2026-18577 · Claude · Cloudflare Tunnel · LangGraph · N-able · N-central