Briev
Live
Technology

CISA orders federal agencies to fix critical N-able ‘God mode’ bug within three days

The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2026-18577 to its KEV list and gave federal bodies three days to apply a hot-fix for a N-central flaw that lets attackers seize full admin control.

The Cybersecurity and Infrastructure Security Agency (CISA) has placed the N-able N-central vulnerability (CVE-2026-18577, CVSS 8.2) on its Known Exploited Vulnerabilities catalog, triggering a three-day deadline for all Federal Civilian Executive Branch agencies to install the vendor’s hot-fix. The flaw, described as a “God mode” weakness, grants an attacker full administrative access to the N-central management console, effectively the same privileges held by trusted network operations staff.

Huntress analysts observed that compromised consoles have been used to move laterally onto managed endpoints and to create Cloudflare-based tunnels for long-term network footholds. N-able disclosed the issue on August 2 after confirming exploitation began on July 31, and advised customers unable to patch to disable the service temporarily. By early August, most cloud-hosted instances were patched, though roughly 29 % of self-hosted servers remained exposed. Health-sector advisories from NHS England and Belgium’s Centre for Cybersecurity echo the urgency, warning of likely further attacks if the vulnerability is not remediated promptly.

Why it matters

A flaw that gives attackers full control of MSP consoles could compromise thousands of managed networks, including critical government systems.

In this story

N-ableCVE-2026-18577CISAKEVN-centralhot-fixmanaged service providerexploitCloudflare tunnel