August 17, 2026

How a Patch-Bypass Flaw Opened the Door to StormEncryptor Ransomware

No items found.

In early August, threat actors exploited an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) platform widely used by managed service providers. Because RMM tools have elevated access across entire networks, unauthenticated attackers were able to reach managed client endpoints without compromising individual devices.

N-able first flagged anomalous activity through its Adlumin MDR service on July 31 and confirmed exploitation the next day. Guidance and an initial hotfix went out August 2. CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on August 3, then added its predecessor, CVE-2026-18556, two days later. Both carry a CVSS score of 8.2. The relationship between the two matters more than the score: CVE-2026-18577 is a bypass of the patch for CVE-2026-18556. N-able closed a specific set of checks the first time, and someone found a way around those exact checks. Anyone who patched the earlier flaw and considered the matter closed was still exposed.

After the bypass, attackers used Take Control, N-central's built-in remote access feature, to reach managed endpoints, then quietly registered a Cloudflare Tunnel service on those machines to establish persistence. Take Control is legitimate. Cloudflared is signed software most security tools wave through, and its traffic looks like any other encrypted connection to a CDN. The attackers were hiding inside tools defenders had already decided to trust.

Microsoft Threat Intelligence ties the activity, with moderate confidence, to Storm-1175, a financially motivated group previously linked to Medusa ransomware. Some reporting adds a probable China nexus, though Microsoft's own assessment centers on financial motive rather than state sponsorship, and both points are worth holding loosely. The group has moved on from Medusa to a new C++ strain called StormEncryptor, which appends a .encrypted extension and gives victims three days to pay before their data goes up for sale. For lateral movement, the crew leaned on familiar commodity tools: AnyDesk, SimpleHelp, Advanced IP Scanner and Mimikatz.

Response and Takeaways

Hosted N-central customers are patched automatically. On-premises deployments are not, and those admins need 2026.3 Hotfix 2 (build 2026.3.1.10) applied outside the normal cycle. Push the agent update to endpoints after patching the server, since the server fix alone doesn't close every downstream gap.

Patching addresses tomorrow's risk, not today's. Given that exploitation began before most organizations knew there was a problem, any internet-reachable, unpatched instance during that window should be treated as compromised until proven otherwise. Some steps to take:

  • Look for rogue cloudflared services and a suspicious svchost.exe in user Documents folders (an artifact N-able called out specifically).
  • Pull Take Control session logs.
  • Check for new admin accounts.
  • Review service installation events and comb authentication logs back through late July. 

N-able has published network indicators worth checking against firewall and proxy history, though the list has grown since its first release and shouldn't be treated as final:

  • 173.249.252.200
  • 87.249.138.34
  • 37.19.210.32
  • 37.153.90.88
  • 92.118.112.181
  • 68.235.46.214

The larger point outlasts this CVE. RMM platforms concentrate administrative reach into one place, which makes them worth more to an attacker than any single endpoint. New York's Department of Financial Services issued an industry letter on this campaign on August 11, a sign regulators are starting to treat exposure in management tooling as first-class risk.

Published By: Daniel Parker, VP of Ethical Hacking, NetWorks Group

Publish Date: August 17, 2026

References

Rapid7. "CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild." August 4, 2026, updated August 14, 2026. rapid7.com/blog/post/etr-cve-2026-18577-n-able-n-central-authentication-bypass-exploited-in-the-wild

N-able. N-central security advisories and Hotfix 2 mitigation notice. August 2 and August 6, 2026. status.n-able.com

CISA. "CISA Adds One Known Exploited Vulnerability to Catalog." August 3, 2026. cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog

The Hacker News. "CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises." August 2026. thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html

The Record (Recorded Future News). "China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns." August 2026. therecord.media/china-hackers-ransomware-microsoft

BleepingComputer. "New StormEncryptor ransomware used by former Medusa affiliate." August 2026. bleepingcomputer.com/news/security/new-stormencryptor-ransomware-used-by-former-medusa-affiliate

New York Department of Financial Services. Industry Letter IL20260811, "Cyber Threat Alert: N-central." August 11, 2026. dfs.ny.gov

Think We Can Help?

Let’s Talk