CARDS
CARDS
This campaign card tracks exploitation of the linked N-able N-central bypasses CVE-2026-18556 and CVE-2026-18577. The August 10 delta adds a bounded Microsoft-linked assessment that recent Storm-1175 intrusions likely used CVE-2026-18577 for initial access before deploying StormEncryptor. It does not assign Storm-1175 to every N-central exploitation event or claim a complete victim population.
Last updated Aug 10, 2026, 4:00 PM EDT
Evidence Boundary
Bottom Line Up Front
This campaign card tracks exploitation of the linked N-able N-central bypasses CVE-2026-18556 and CVE-2026-18577. The August 10 delta adds a bounded Microsoft-linked assessment that recent Storm-1175 intrusions likely used CVE-2026-18577 for initial access before deploying StormEncryptor. It does not assign Storm-1175 to every N-central exploitation event or claim a complete victim population.[1][2][3][4][5]
Unauthorized N-central administrative access can inherit remote-management reach across customer tenants and endpoints. In the reported Storm-1175 intrusion set, that path can extend into credential theft, discovery, remote-tool deployment, exfiltration, and StormEncryptor file encryption.[1][2][3][4][5]
Upgrade to build 2026.3.1.7 or later; preserve control-plane and perimeter evidence; investigate administrators, sessions, jobs, scripts, AnyDesk/SimpleHelp, Mimikatz, Cloudflared, encryption, and exfiltration; hunt the vendor and StormEncryptor artifacts; and scope each customer separately without assuming universal Storm-1175 attribution.[1][2][3][4][5]
Decision Summary
This campaign card tracks exploitation of the linked N-able N-central bypasses CVE-2026-18556 and CVE-2026-18577. The August 10 delta adds a bounded Microsoft-linked assessment that recent Storm-1175 intrusions likely used CVE-2026-18577 for initial access before deploying StormEncryptor. It does not assign Storm-1175 to every N-central exploitation event or claim a complete victim population.
The retained record scopes this as rmm control-plane authentication bypass / administrative account takeover / credential theft / downstream remote access / ransomware activity during August 1, 2026 onward. Unauthorized N-central administrative access can inherit remote-management reach across customer tenants and endpoints. In the reported Storm-1175 intrusion set, that path can extend into credential theft, discovery, remote-tool deployment, exfiltration, and StormEncryptor file encryption.[1][2][3][4][5]
Upgrade to build 2026.3.1.7 or later; preserve control-plane and perimeter evidence; investigate administrators, sessions, jobs, scripts, AnyDesk/SimpleHelp, Mimikatz, Cloudflared, encryption, and exfiltration; hunt the vendor and StormEncryptor artifacts; and scope each customer separately without assuming universal Storm-1175 attribution.[1][2][3][4][5]
Confirmed reporting is separated from attribution, victim, and prevalence claims that the retained sources do not establish. Confidence: High for the linked vulnerability pair, fixed build, vendor-confirmed exploitation posture, and N-able observables; medium for the reported likely Storm-1175/CVE-2026-18577 link; victim population and universal attribution are not established..[1][2][3][4][5]
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Likely initial access is not confirmed universal attribution. Cloudflared and remote tools are legitimate dual-use software; the N-able IPs are time-sensitive; historical Storm-1175 IOCs are not StormEncryptor-specific; vulnerable does not equal compromised.
Evidence Controls
IntelliOS
Citations