CARDS
CARDS
This campaign card tracks source-bounded exploitation of two linked N-able N-central authentication bypasses: CVE-2026-18556 and the incomplete-fix path CVE-2026-18577. It connects the vendor-confirmed control-plane issue to downstream managed-device hunting without assigning a named actor, ransomware family, or complete victim population.
Last updated Aug 03, 2026, 12:00 PM EDT
Actor Mapping
Targeting
Tradecraft
Tools / Observables
Source Reconciliation
Campaign rows are retained as source-backed context. Actor mappings do not automatically merge actor records; SOCRadar, MITRE, Mandiant, CrowdStrike, Microsoft, and other future sources can disagree on boundaries, aliases, or campaign ownership.
Cloudflared is legitimate dual-use software; the published IPs are time-sensitive hunt pivots; vulnerable does not equal compromised; one managed customer finding does not prove impact to every customer.
Evidence Controls
IntelliOS
Citations