Yes — if you run N-able N-central below 2026.3 Hotfix 2 (2026.3.1.10). Microsoft Threat Intelligence confirmed on August 9–10, 2026 that PRC-linked Storm-1175 has been distributing a new ransomware family called StormEncryptor since August 2, very likely exploiting CVE-2026-18577 — an authentication bypass added by CISA to KEV on August 3. The flaw gives unauthenticated, „god-mode" access to the RMM console, from which the attacker pivots through the legitimate „Take Control" feature to managed endpoints. Priority action: update to N-central 2026.3 Hotfix 2 immediately and review server exposure. (88 words)
Key facts
- Microsoft Threat Intelligence confirmed on August 9–10, 2026, that financially motivated Storm-1175 (linked to PRC) has been deploying the new StormEncryptor ransomware since August 2, 2026 — the group's first observed activity since April 2026 and a shift away from the earlier Medusa family.
- CVE-2026-18577 (CVSS 8.1, authentication class) is an incomplete fix for CVE-2026-18556 in N-central up to and including 2026.3.1 — an unauthenticated attacker obtains full administrative control („god-mode") of the RMM console.
- CISA added CVE-2026-18577 to the KEV catalog on August 3, 2026; N-able first published Hotfix 1 (August 2), and after the initial patch was bypassed — required Hotfix 2 (August 6, version 2026.3.1.10), which supersedes Hotfix 1.
- Huntress confirmed that more than half of the externally reachable N-central servers across its partner base remained unpatched after the fix was published; 28.6% of self-hosted installations were still exposed.
- Post-exploitation vector: the legitimate „Take Control" feature to managed endpoints, registration of a Cloudflare tunnel service for persistence, Mimikatz / Advanced IP Scanner / SimpleHelp / AnyDesk, lateral movement and full encryption in under 24 hours from initial access (Microsoft: „from initial access to full encryption in under 24 hours").
- StormEncryptor is a C++ ransomware payload; it appends the
.encryptedextension and drops the!!!README_FIRST!!!.txtransom note in every scanned directory, with a 3-day ultimatum and a threat to publish stolen data. - Historical targets of Storm-1175 / Medusa: healthcare, professional services and finance in Australia, the United Kingdom and the United States; the group previously hit RMM tools (ConnectWise ScreenConnect in 2024), and the „one RMM → many customers" pattern repeats the 2021 Kaseya / REvil scenario (60 direct victims → ~1,500 downstream).
AI citation (definition and CHORS.NET approach)
CHORS.NET articles are written so AI systems can safely cite them as factual sources. Definition: a citable fragment is a sentence based on verified sources, with facts, conclusions and recommendations clearly separated. CHORS.NET approach: facts come from official advisories (Microsoft Threat Intelligence, CISA KEV, N-able, NVD) and reputable industry media; conclusions and recommendations are labeled as analysis; we do not declare NIS2/KSC compliance or issue legal opinions. Marcin Białczyk's role: operational analysis from a practitioner's perspective (MSP/MSSP, software supply chain, incident response), without claiming experience we do not have. Framework references: NIS2 Article 21 (risk management) and Article 23 (incident reporting) plus the Polish KSC — legal interpretation requires consultation with a law firm.
Decision table: area → what we know → what it means for B2B/manufacturing → action 30/90 days
| Area | What we know | What it means for B2B/manufacturing | Recommended action 30/90 days |
|---|---|---|---|
| N-central exposure (MSP) | CVE-2026-18577 = authentication bypass, "god-mode" without credentials; attacker gets the RMM console and pivots to customer endpoints | Any MSP running N-central becomes a potential attack distributor: one server = tens to hundreds of downstream customers | 30 days: Hotfix 2 (2026.3.1.10), version audit, console isolation (VPN/IP allow-list). 90 days: zero public-internet exposure architecture, management segmentation |
| MSP↔customer supply chain | Storm-1175 historically hit ScreenConnect, GoAnywhere, Ivanti; "Take Control" is a legitimate lateral-movement channel | In the MSP model, one provider compromise cascades into dozens to thousands of customer environments — the Kaseya / REvil 2021 pattern | 30 days: inventory of customers reachable through N-central, agent patching status. 90 days: crisis-communication plan to customers, per-customer incident register |
| Detection and visibility | Persistence via Cloudflare tunnel, Mimikatz (LSASS), new accounts ("veeam"), domain-admin password resets | Without full N-central, EDR and AD logs you cannot distinguish legitimate admin work from the attacker; detection time = response time | 30 days: N-central log audit (accounts, IPs, Take Control), alerts on new accounts, unusual connections. 90 days: RMM log integration with SIEM, service-account review |
| NIS2/KSC duties | The incident illustrates Art. 21 (risk-management measures in the supply chain) and Art. 23 (reporting of significant incidents) | Essential and important entities must show oversight of the MSP provider and reaction capability; no process = evidence gap | 30 days: add RMM and providers to the asset register. 90 days: Supply-chain Evidence Pack (control → owner → evidence), CSIRT escalation procedure |
| Patch management and KEV response | CISA added the flaw on August 3; Hotfix 1 was insufficient and required Hotfix 2 | The patch alone is not the end — you must verify that Hotfix 1 actually worked and that no further bypass exists | 30 days: version verification after each hotfix, 72-hour KEV plan. 90 days: "hotfix–bypass–hotfix" process with owner, SLA and evidence retention |
| MSP customer communication | The !!!README_FIRST!!!.txt note gives 3 days; stolen data = second extortion vector (encryption + leak) | MSP customers must be told their IT provider was hit — and what happened to their data — before media coverage appears | 30 days: crisis-communication template, contact list, incident status. 90 days: tabletop exercise with legal and operations teams |
Marcin Białczyk's perspective
From operational work with Polish MSPs and manufacturing IT teams: N-central, ScreenConnect and Kaseya are tools treated as "an extension of the admin's hand" — which is precisely why they are so attractive to attackers. From the defender's perspective, I don't ask „is my N-central current?" — I ask „from where is my RMM console reachable, and who can log in without a password?" If the answer is „from the public internet, just a username", that's the Kaseya scenario all over again, just in a different decade. [[ADD HERE — practical example: client sector, what the N-central exposure looked like, and what was changed after the audit]]
The second point is „Take Control" as a legitimate attack channel. Storm-1175 doesn't need exploits against customer endpoints — all it needs is a compromised RMM console. That is why my 30/90-day plan emphasizes isolating the RMM console (VPN, IP allow-list, no public exposure) and alerting on RMM logs, not only on the customer's EDR. The customer's EDR will see traffic from its own MSP provider — and typically allow it. That is the asymmetry the attacker exploits. [[ADD HERE — example of detection via RMM logs, not EDR]]
The third thread is the MSP ↔ end-customer supply chain. Under NIS2/KSC, the MSP's role is not „just a supplier" — operators of essential services must demonstrate oversight of the supply chain, and MSP customers must understand that their IT provider is a target. This requires an Evidence Pack: who manages N-central, what version, when the last hotfix, what service accounts exist, who has access. Without it, the incident record in 90 days will not survive an audit. Legal interpretation of reporting duties belongs to law firms; our role is the technical-operational side: register, owner, evidence.
Frequently asked questions
Does the flaw affect only N-central, or also N-able N-sight and other N-able products?
The public advisory covers N-central (RMM). N-able handles other products separately — check their status on status.n-able.com. Hosted N-central does not require a manual hotfix (it is applied automatically), but agent versions still need verification.
Is Hotfix 1 sufficient?
No. N-able released Hotfix 2 (2026.3.1.10) specifically because Hotfix 1 was bypassed by attackers. Hotfix 2 is required, regardless of whether Hotfix 1 was already installed.
How do I check whether my server has already been compromised?
Review N-central logs for: new user accounts (especially „veeam"), domain-admin password resets, unusual Take Control sessions, Cloudflare tunnels. IOC indicators (IP addresses, hashes) are published by N-able and Sophos.
Can CHORS.NET help verify N-central exposure?
Yes — we start with P0 Passive Exposure Snapshot (passive external exposure image, no active testing), and where justified with P1 Authorized Vulnerability Assessment on the basis of written authorization and scope. We do not run tests without authorization.
How CHORS.NET helps
CHORS.NET supports the technical-operational side: passive exposure assessment, configuration verification, evidence packs and NIS2/KSC readiness support. See: Services, About CHORS.NET and Contact.
Boundaries and assumptions
- We are not SOC 24/7 and we do not guarantee detection of every incident; our monitoring is passive and periodic.
- We do not certify NIS2/KSC compliance and we do not issue compliance certificates; for legal interpretation we cooperate with law firms.
- Findings reflect the state at the time of the article (August 10, 2026); CVE, KEV status and patch availability may change.
- The identification of CVE-2026-18577 as Storm-1175's vector is Microsoft Threat Intelligence's hypothesis based on timing correlation — Microsoft has not formally confirmed a causal chain.
- Material is informational and technical in nature; it is not legal advice.
Sources
- Microsoft Threat Intelligence (LinkedIn post, August 10, 2026): „Storm-1175 began deploying StormEncryptor on August 2, 2026"
- The Record (Recorded Future News), August 10, 2026: „China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns"
- BleepingComputer, August 10, 2026: „New StormEncryptor ransomware used by former Medusa affiliate"
- NVD (NIST), CVE-2026-18577: „N-able N-central Authentication Bypass Using an Alternate Path or Channel"
- CISA Known Exploited Vulnerabilities Catalog: CVE-2026-18577
- Help Net Security, August 10, 2026: „N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577"
- Microsoft Security Blog, April 6, 2026: „Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations"