On August 1, 2026, N-able released an advisory disclosing active exploitation of a vulnerability affecting the N-central remote monitoring and management (RMM) platform. The vulnerability (CVE-2026-18577) is characterized as an authentication bypass that allows privileged access to the management interface of the platform in both hosted and on-premises implementations. An incomplete fix for CVE-2026-18556 published on August 1 has been reported as the underlying cause, though N-able has not directly confirmed the assertion. N-able published a hotfix to address CVE-2026-18577 on August 2 and included details about observed exploitation activity. On August 4, N-able published an additional advisory indicating that exploitation began on July 31 as a zero-day vulnerability.
Sophos Counter Threat Unit™ (CTU) researchers identified a single compromised organization in Sophos customer telemetry and have observed no evidence that compromises are widespread. The victim was compromised at approximately 08:00 UTC on August 3, and the threat actor used the compromised N-central server to access high-value endpoints such as a backup server, domain controllers, and application servers.
Attack details
During the intrusion, the threat actor created a new domain account named “veeam” and reset the passwords of several existing domain administrator accounts. Several “net user” commands were executed to enumerate existing accounts within the network. Additionally, two network reconnaissance commands were executed:
- nltest /dclist:
- net group “domain admins” /domain
With the remote control ability granted through exploitation of N-central, the threat actor deployed numerous RMM tools to accessible endpoints. These tools included AnyDesk (AnyDesk.exe), TacticalRMM (installed via a install_server.ps1 PowerShell script and package tacticalagent-v2.11.0-windows-amd64.exe), TeamViewer (team.msi and TeamViewer_Setup.exe), RustDesk (rustdesk.exe), SimpleHelp (service64off.exe), and HopToDesk. Cloudflare Tunnel (cloudflared.exe) was installed on several hosts but was renamed as MicrosoftEdgeUpdate64.exe or msmp.exe to masquerade as a benign file. The threat actor used this tunnel to obtain persistent remote access to the environment.
N-able indicated that a file named svchost.exe in a user’s Documents directory (i.e., %USERPROFILE%\Documents) can reveal that the system has been compromised, but CTU researchers did not observe this filename in the victimized Sophos customer’s environment. It is possible that svchost.exe is one of the legitimate Windows filenames used by the threat actors to obscure cloudflared.exe.
The threat actor used the “tasklist” command with output piped to “findstr ms” and “findstr soph” to identify hosts running Microsoft Defender or Sophos agents, respectively. When a security product was identified, the PhantomKiller endpoint detection and response (EDR) evasion tool loaded a driver named k.sys, which was located in C:\ProgramData\AnyDesk. In one instance, PhantomKiller (named 9.exe) terminated the Sophos File Scanner process (sophosfilescanner.exe).
Recommendations, countermeasures, and indicators
CTU™ researchers advise organizations that use N-central to apply the hotfix as appropriate in their environments as soon as possible. Organizations should also search their environment for evidence that could indicate a compromise and respond accordingly.
The following Sophos countermeasure relates to this threat:
- CXmal/KillAV-BR
The threat indicators in Table 1 can be used to detect activity related to this threat. Note that IP addresses can be reallocated. The domains and IP addresses may contain malicious content, so consider the risks before opening them in a browser.
| Indicator | Type | Context |
| 173[.]249[.]252[.]200 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 172[.]249[.]252[.]176 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 87[.]249[.]138[.]34 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected NordVPN egress node will likely be associated with unrelated traffic) |
| 37[.]19[.]210[.]32 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) (Note that this suspected Mullvad VPN egress node will likely be associated with unrelated traffic) |
| 68[.]235[.]46[.]214 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 68[.]235[.]46[.]235 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 37[.]153[.]90[.]88 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 92[.]118[.]112[.]181 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 23[.]234[.]94[.]43 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| 185[.]156[.]46[.]150 | IP address | Used to identify and exploit N-able N-central vulnerability (CVE-2026-18577) |
| who-ripped-one[.]direct[.]quickconnect[.]to | Domain name | C2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577) |
| mousears[.]synology[.]me | Domain name | C2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577) |
| wagoosh[.]direct[.]quickconnect[.]to | Domain name | C2 server used by RMM tool in exploitation of N-able N-central vulnerability (CVE-2026-18577) |
| api[.]mendoratech[.]health | Domain name | TacticalRMM server used during exploitation of N-able N-central vulnerability (CVE-2026-18577) |
Table 1: Indicators for this threat

