The Hacker News · Aug 5
CISA says an actively exploited N-central bug needs patching now
CISA added an N-able N-central authentication-bypass flaw (CVE-2026-18556, CVSS 8.2) to its known-exploited catalog, and an incomplete first fix opened a second exploited bug (CVE-2026-18577). Two more actively exploited flaws landed the same week: a Langflow unauthenticated remote-code-execution hole (CVE-2026-9198, CVSS 9.8) and an Apache Tomcat encryption bypass, with a federal patch deadline of August 7, 2026.
▸ The MSP Angle
Is my RMM tool a target for attackers right now?
N-central sits at the center of many MSP stacks, so an exploited auth bypass is a direct line into every client you manage from one console. Confirm your build is patched past both CVEs today, hunt for the Langflow and Tomcat flaws anywhere in your environment, and treat your own tooling as the first thing attackers will probe. Your clients inherit whatever risk your management plane carries.