AL
Analyst accessPublic view · sign in

Vulnerability threat dossier

CVE-2026-18577

Vendor unknownProduct mapping pending

Metadata pending authoritative retrieval.

VTP deterministic threat50.8of 100 · CVSS excluded

VTP analyst assessment

No AI candidate assessment for this subject

AI-assisted analytical recommendationDoes not set factual exploitation state
AI classificationNO ALERT
AI priorityNONE
AI confidenceUnknown
Public exploitation · VTP factKEV

Assessment

The latest persisted AI review did not propose this CVE for analyst escalation. Deterministic monitoring remains authoritative for the factual states below.

Why it matters

Unknown from persisted AI analysis.

Evidence

No AI candidate evidence set is persisted for this CVE.

Uncertainties

No first-party sensor telemetry is configured. Local exploitation observation is unknown.

Next watchpoint · deterministic

A validated functional exploit or automated exploitation capability would materially change this assessment.

AI analysis history (0)
    Technical severityUNKNOWNCVSS unknown · technical context
    Public exploitationKEVGlobal public evidence
    Exploit maturityTECHNICAL DETAILSReliability not implied
    EPSS0.0490th percentile · prediction
    Evidence confidence82%Strongest independent active claim
    VelocitySTABLEMaterial events only
    First-party telemetryNo first-party sensor telemetry configured.
    Availability: NO_SENSOR_CONFIGURED · Evidence: UNKNOWN
    01

    VTP deterministic assessment

    Why this matters

    1. 01

      CISA KEV lists this vulnerability as known to be exploited globally.

    2. 02

      EPSS is 0.04; this is predictive context, not exploitation evidence.

    3. 03

      No first-party sensor telemetry is configured; first-party observation is unknown.

    02

    Material change ledger

    What changed

    ACTIVE EXPLOITATIONActive Exploitation
    RESEARCH PUBLICATIONNew technical research
    KEV ADDEDCISA KEV entry added
    03

    Claim provenance

    Evidence and source independence

    6publications detected
    6underlying evidence chains

    1 primary sources · 0 dependent secondary reports · 5 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

    Source claimURGENT PATCHINGSOURCE URGES URGENT PATCHING
    62%claim confidence
    UNKNOWNreport:00337214452ea74b2dc66b71da36047026721df821181c68dfd03e0ef30b12c0ACTIVE
    Evidence
    Source claimZERO DAYPUBLICATION REPORTS ZERO DAY
    64%claim confidence
    UNKNOWNreport:a426db854844926de80aab40cdf057658c1f159c812a4d9018e5c4d19f09323dACTIVE
    Evidence
    Source claimACTIVE EXPLOITATIONSOURCE REPORTS ACTIVE EXPLOITATION
    82%claim confidence
    INDEPENDENTreport:25495a8ce61ce9a485c151c967ad550cea58f5ade54ab3fb0ca34593901ad4a2ACTIVE
    Evidence
    04

    Event history

    Threat timeline

    1. 17:4210 Aug
      URGENT PATCHING

      Urgent Patching

      BleepingComputer supplied a deterministically extracted signal; review the linked evidence before escalation.

    2. 06:5708 Aug
      ZERO DAY

      Zero Day

      The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.

    3. 11:1104 Aug
      ACTIVE EXPLOITATION

      Active Exploitation

      Rapid7 Research supplied a deterministically extracted signal; review the linked evidence before escalation.

    4. 11:1104 Aug
      RESEARCH PUBLICATION

      New technical research

      Rapid7 Research published evidence linked to CVE-2026-18577.

    5. 00:0003 Aug
      KEV ADDED

      CISA KEV entry added

      CISA lists global known exploitation. This is not a VTP sensor observation.

    05

    Original publications

    Source record

    New StormEncryptor ransomware used by former Medusa affiliate

    A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

    CVE-2026-18577
    Separate evidence group
    Original

    China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

    Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said. "StormEncryptor is written in C++ and appends the file name extension .encrypted

    CVE-2023-37679CVE-2023-43208CVE-2023-48788CVE-2024-1708CVE-2024-1709CVE-2024-27198CVE-2024-27199CVE-2025-10035CVE-2026-18556CVE-2026-18577
    Separate evidence group
    Original

    ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

    CVE-2013-3821CVE-2025-8943CVE-2026-14869CVE-2026-15307CVE-2026-16496CVE-2026-16498CVE-2026-17583CVE-2026-18236CVE-2026-18497CVE-2026-18556CVE-2026-18577CVE-2026-18830CVE-2026-19137CVE-2026-19149CVE-2026-19154CVE-2026-19157CVE-2026-19170CVE-2026-19172CVE-2026-20267CVE-2026-20272CVE-2026-20303CVE-2026-20304CVE-2026-20310CVE-2026-34348CVE-2026-41679CVE-2026-50481CVE-2026-50515CVE-2026-56162CVE-2026-56181CVE-2026-58048CVE-2026-58072CVE-2026-58073CVE-2026-59115CVE-2026-59774CVE-2026-62830CVE-2026-63508CVE-2026-63913CVE-2026-64531CVE-2026-64561CVE-2026-64564CVE-2026-64638CVE-2026-64650CVE-2026-64651CVE-2026-65400CVE-2026-65667CVE-2026-8496
    Separate evidence group
    Original

    N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

    N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said. "This is not a duplicate of our

    CVE-2026-18556CVE-2026-18577
    Separate evidence group
    Original

    CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

    Overview On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments. N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams to centrally administer servers, workstations, network devices, and other managed assets. Because the platform operates with extensive administrative privileges across customer environments, successful compromise of an N-central server can provide attackers with an efficient path to compromise downstream managed systems. According to N-able, exploitation of CVE-2026-18577 has been observed in the wild since August 1, 2026 . Following successful exploitation, attackers leveraged the platform's Take Control functionality to remotely access managed endpoints, and deployed Cloudflare Tunnel (cloudflared) to establish persistent remote access. On August 3, 2026, CVE-2026-18577 was added to CISA’s Known Exploited Vulnerability (KEV) catalog and on August 5, 2026, CVE-2026-18556 was also added to the catalog. Mitigation guidance Organizations operating vulnerable N-central deployments should prioritize remediation on an urgent basis, outside of normal patching schedules. Hosted N-central environments are upgraded automatically by the vendor, while on-premise deployments require manual remediation. Affected versions: All versions of N-able N-central up to and including version 2026.3.1, prior to Hotfix 1. Fixed version: N-able N-central 2026.3.1 Hotfix 1 (2026.3.1.7). The vendor also recommends: Upgrading N-central agents after applying the server hotfix. Reviewing systems for indicators of compromise. Contacting N-able Support immediately if evidence of compromise is discovered. Engaging internal incident response teams if malicious activity is identified. For further information, see the vendor advisory . IOCs N-able has published several artifacts that administrators should investigate during incident response. Endpoint Artifacts: Presence of a Cloudflared service. A suspicious svchost.exe located within the user's Documents folder. Network Indicators: Administrators should review historical network logs for inbound or outbound communication involving the malicious IP addresses identified by the vendor: 173[.]249[.]252[.]200 87[.]249[.]138[.]34 37[.]19[.]210[.]32 37[.]153[.]90[.]88 92[.]118[.]112[.]181 68[.]235[.]46[.]214 Organizations should also review: Authentication logs Administrative account creation or modification Take Control session activity Remote management logs Windows service installation events To assist affected organizations running N-central, the vendor has provided a detection template for CVE-2026-18577, which organizations can use to help identify potential compromise. Rapid7 customers Exposure Command, InsightVM, and Nexpose Exposure Command, InsightVM, and Nexpose customers can assess exposure to CVE-2026-18577 and CVE-2026-18556 with vulnerability checks available in the August 4 content release. Note that potential check type must be enabled in the scan template before scanning. Updates August 4, 2026: Initial publication. August 4, 2026: Updated Rapid7 customers section to reflect the availability of vulnerability checks. August 7, 2026: Updated the Overview and Rapid7 Customers sections to indicate addition of CVE-2026-18556 to CISA KEV and availability of vulnerability checks.

    CVE-2026-18556CVE-2026-18577
    Separate evidence group
    Original

    Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

    Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.

    CVE-2026-18577
    Separate evidence group
    Original
    06

    Technical vulnerability data

    Context, not threat proof

    VTP threat score50.8vtp-threat-v1-public
    Public exploitation30 / 30
    EPSS prediction0.82 / 20
    Exploit availability2.5 / 15
    Source independence7.5 / 15
    Intelligence recency10 / 10
    Threat acceleration0 / 10
    CVSS technical severityExcluded
    CVSS
    Unknown · UNKNOWN
    Vector
    Unknown
    CWE
    Unknown
    CPE records
    0
    Deterministic history records
    8
    07

    Raw observations

    First-party sensor records

    No first-party sensor telemetry configured.