Storm-1175 Deploys New StormEncryptor Ransomware as N-central Authentication Bypass Is Actively Exploited
Microsoft assessed with qualified confidence that Storm-1175, a financially motivated ransomware group, likely exploited CVE-2026-18577, an authentication-bypass flaw in N-able N-central, beginning on the day the vulnerability was publicly disclosed. The flaw allowed unauthenticated remote administrative access to N-central, which manages endpoints across MSP customer environments, and attackers used the platform's own Take Control feature to pivot to managed devices and install persistent Cloudflare tunnels that survived credential revocation. N-able has released a second hotfix that supersedes the first, and operators who applied only the initial patch are not fully protected.