Hackers exploit N-central flaw to deploy new ransomware
Microsoft says China-linked Storm-1175 likely used CVE-2026-18577 in N-central to push StormEncryptor ransomware through IT providers.
By Sam Reyes · Published · Updated · 4 min read

A China-linked, financially motivated group is likely exploiting a critical flaw in N-central, software used by IT service providers to manage their clients' computers, The Record reports.
The vulnerability
- CVE-2026-18577 affects N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers (MSPs).
- Huntress says it gives attackers "unauthenticated, 'god-mode' access" — full admin control with no password.
The attacks
- Microsoft says Storm-1175 began deploying a new ransomware strain, StormEncryptor, on August 2 — the same day the flaw was disclosed.
- The group previously used Medusa ransomware against healthcare, professional services and finance organizations in Australia, the UK and the US.
- Microsoft has seen it move from first access to full encryption in under 24 hours.
Why it matters
One compromised RMM server can reach every client an IT provider manages. That turns a single flaw into a supply-chain attack on dozens or hundreds of businesses at once.
What to do
- MSPs: patch N-central immediately, restrict its internet exposure and review admin accounts.
- Businesses that use an MSP: ask your provider whether it uses N-central and whether it has patched.
- Keep offline backups that your IT provider's tools cannot reach.


