
CVE-2026-18577: N-able RMM — Rapid Ransomware Deployment Risk (August 2026)
CVE-2026-18577 — N-able RMM
CVE-2026-18577 is a critical vulnerability in N-able Remote Monitoring and Management (RMM) software, rated high severity and currently under active exploitation by the China-linked Storm-1175 threat actor. The flaw enables unauthenticated attackers to gain initial access and deploy ransomware, including the new StormEncryptor variant, across targeted environments. There is no evidence of a working workaround; patching is mandatory.
Attack Vector
Storm-1175 exploits CVE-2026-18577 within days of disclosure, leveraging the vulnerability to compromise unpatched N-able RMM instances exposed to the internet. Once access is gained, the group deploys StormEncryptor ransomware, which encrypts files (adding the .encrypted extension) and drops ransom notes demanding payment. The attack chain is rapid, with ransomware deployment occurring within hours of initial compromise. No specific IOCs are provided, but look for unusual RMM activity and sudden file extension changes.
Who Is at Risk
All organizations running unpatched N-able RMM are at immediate risk, especially those in healthcare, education, and finance sectors in the US, UK, and Australia. Cloud-hosted and on-premises deployments are both vulnerable. There are confirmed incidents in these sectors, but any exposed N-able RMM instance is a potential target.
Patch & Mitigate
- Patch: Apply the latest N-able RMM security update addressing CVE-2026-18577 by August 10, 2026.
- Workaround: No reliable workaround exists; restrict RMM access to trusted IPs as a temporary measure.
- Detect: Monitor for unauthorized RMM logins, creation of .encrypted files, and new ransom note artifacts. Review logs for suspicious remote actions and privilege escalations.
MITRE ATT&CK
- TA0001 — Initial Access: Storm-1175 exploits public-facing N-able RMM to gain entry.
- TA0005 — Defense Evasion: Ransomware is deployed rapidly to avoid detection and response.
- TA0010 — Exfiltration: Data theft is likely prior to encryption, increasing impact.
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

