
Two related flaws (CVE 2026 18556 and CVE 2026 18577, CVSS ~8.2) are now on CISA’s Known Exploited Vulnerabilities (KEV) catalog. Attackers are gaining full administrative (“god mode”) access to N central consoles, abusing the built in Take Control feature to pivot into managed endpoints, and establishing persistence with tools like Cloudflare Tunnel.
If you run N central especially on premises this is a time critical incident.
What to do now ?
• Patch immediately: On premises must be on Hotfix 2 (build 2026.3.1.10). Cloud tenants were auto patched but should still validate build/version in the portal.
• Validate the control plane: Confirm console health, device check ins, and that Take Control behaves as expected; document pre/post build numbers and keep a defined rollback decision point.
• Hunt for abuse: Review Take Control session logs for off hours/unexpected admins/targets; look for new remote tools/tunnels (e.g., cloudflared) on endpoints.
• Harden access: Don’t expose the console to the public internet; restrict via firewall/IP allow lists or VPN, enforce SSO/MFA, apply least privilege, and segment management networks.
How Storage Guardian helps right now ?
Treat this as a priority incident and execute a controlled, auditable response even if your RMM control plane is untrusted.
• Automated failover workflows: Predefine and trigger recovery steps without manual intervention to reduce RTO if the N central server must be isolated or rebuilt.
• Incident response templates (PICERL/ISHP): Structure your response to auth bypass, account takeover, and lateral movement, including decision gates on isolate vs. rebuild.
• Multi channel disaster declaration: Declare via phone/SMS/web with PIN based auth so recovery starts even if email/console access is compromised.
• Integrated MDR/BDR coordination: Align security and recovery teams from a single window during active incidents.
Bottom line: Delaying patching materially increases the risk of full console takeover and downstream compromise of managed environments.
Need help turning this into a contained, documented incident with validated recovery paths? Message our team at Storage Guardian we’ll walk you through DR Runbook execution and NIST 2.0 aligned response.