N-able RMM Compromise, SonicWall Ransomware Intrusions, and OWAReaper Persistence Lead This Week's CVE Priorities - Safe Security

N-able RMM Compromise, SonicWall Ransomware Intrusions, and OWAReaper Persistence Lead This Week’s CVE Priorities

Aug 4, 2026 10 minute read

By SAFE Threat Research Team

This week’s exploitation activity is concentrated on technologies that already hold administrative trust across enterprise environments. Attackers exploited N-able N-central to obtain remote administrative access and use the platform’s Take Control capability to reach managed endpoints. Meanwhile, vulnerabilities in SonicWall SMA1000 appliances, initially exploited as zero-days, are now being weaponized in ransomware intrusions. An actively exploited static-credential vulnerability in Cisco Secure Firewall Management Center also provides unauthorized access to the firewall management plane and may support broader exploit chains.

Enterprise email and document-based attack paths remain active as well. TA488 is exploiting CVE-2026-42897 in on-premises Microsoft Exchange to deploy OWAReaper, a browser-resident implant designed to persist through OWA data, OAuth tokens, and server-side mailbox permissions. Separately, Cloud Atlas continues to exploit the legacy Microsoft Office Equation Editor vulnerability, CVE-2018-0802, in targeted campaigns, alongside PowerShell malware, reverse tunnels, proxy tooling, and Tor-based access.

Across these cases, the impact is shaped by the affected system’s role. A compromise of an RMM server, VPN appliance, firewall manager, or enterprise mail platform can extend beyond the vulnerable host into managed endpoints, identity infrastructure, internal networks, security controls, and persistent access. Confirmed exploitation, reachability, privilege, and post-compromise scope therefore provide a stronger basis for prioritization than severity scores alone.

Vulnerability Landscape

This week, NVD published 1,937 CVEs, including 764 rated critical or high severity. Public exploit or proof-of-concept code was available for 166 vulnerabilities, while 16 showed stronger weaponized exploit signals.

These metrics establish the scale of the vulnerability landscape, but they do not determine remediation priority on their own. The useful narrowing occurs when exploit availability and confirmed exploitation are correlated with asset reachability, business criticality, and the effectiveness of existing controls.

Trending Vulnerabilities

This week, 21 CVEs showed confirmed exploitation activity, including six newly published vulnerabilities and 15 pre-existing vulnerabilities.

The mix highlights two distinct response requirements. Newly published in-the-wild vulnerabilities require rapid exposure assessment as patches and exploit details emerge. Pre-existing CVEs require continued attention when affected products remain reachable, are widely deployed, are difficult to upgrade, or are no longer supported.

Top CVEs to Watch

N-able N-central CVE-2026-18577: Authentication Bypass Extends Access from the RMM Server to Managed Endpoints

CVE-2026-18577 is an authentication-bypass and account-takeover vulnerability in N-able N-central. This CVE represents an alternate exploitation path related to CVE-2026-18556. Although the earlier issue was addressed in N-central 2026.2, the alternate vector remained exploitable across all releases prior to 2026.3.1.7. The complete fix is provided in N-central 2026.3 Hotfix 1, build 2026.3.1.7.

Observed attacks obtained remote administrative access to N-central servers and then abused the platform’s Take Control capability to connect to systems inside customer-managed environments. On compromised endpoints, attackers registered a Cloudflare tunnel as a service, allowing access to persist even after control of the N-central server was revoked. This makes the issue materially broader than the compromise of a single management console: an affected RMM server can provide a path into multiple downstream customer systems.

Organizations should upgrade to build 2026.3.1.7 and investigate both the N-central server and managed endpoints. Relevant checks include unexpected remote-control sessions, newly registered Cloudflared services, and suspicious svchost.exe files in users’ Documents directories. Exposure of the N-central interface should also be restricted to approved administrative networks rather than left directly reachable from the internet.

SonicWall SMA1000 CVE-2026-15409, CVE-2026-15410: Ransomware Intrusions Reuse VPN Exploit Chain for Root Access

CVE-2026-15409 and CVE-2026-15410 form an actively exploited chain affecting SonicWall SMA1000 remote-access appliances. CVE-2026-15409 is an unauthenticated SSRF vulnerability that can provide access to restricted internal appliance services. CVE-2026-15410 is a post-authentication code-injection vulnerability that allows execution of operating-system commands. When chained, the vulnerabilities can provide root-level control of the appliance.

SAFE previously covered the initial exploitation activity in a July weekly CVE blog, including appliance-level persistence, credential collection, and attempts to pivot from compromised SMA1000 appliances into internal networks.

More recent incident-response activity identifies INC Ransomware as a prominent actor weaponizing the same chain. Root-level access to the appliance can support credential theft, persistent access, and movement into internal corporate environments, expanding the threat beyond the initially observed zero-day campaign.

Organizations should install the latest SonicWall hotfixes and treat appliances that were internet-facing during the exploitation window as potentially compromised. Response should include forensic analysis of the appliance, investigation of activity originating from its internal address, credential and authentication token resets, and re-imaging or redeployment when indicators of compromise are identified.

Cisco Secure Firewall Management Center CVE-2026-20316: Static Credential Enables Unauthorized Access to the Firewall Management Plane

CVE-2026-20316 affects the web interface of Cisco Secure Firewall Management Center. Static credentials for a built-in low-privileged account allow an unauthenticated remote attacker to log in and access sensitive information. Cisco assigns the vulnerability a CVSS score of 5.3, but rates its security impact as High because the initial account can potentially be combined with other FMC vulnerabilities to elevate privileges.

Active exploitation was identified in July 2026. The immediate impact is low-privileged access rather than direct administrative takeover, but the affected system is responsible for centralized firewall configuration, policy administration, and security monitoring. Access to this management plane can therefore support reconnaissance or provide the initial position required for a broader exploit chain.

Cisco has released hotfixes for affected FMC branches and states that no workaround fully addresses the vulnerability. Credential rotation alone is insufficient because the vulnerable credential is embedded in the product. Administrators should install the applicable hotfix and review system logs for execution of package_info.pl against /var/tmp/license.tmp, which Cisco identifies as a possible indication of exploitation. 

Microsoft Exchange CVE-2026-42897: KEV-Listed OWA XSS Exploited to Deploy OWAReaper

CVE-2026-42897 is a high-severity cross-site scripting vulnerability affecting Outlook Web Access in on-premises Microsoft Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition. A crafted email can cause OWA to execute attacker-controlled JavaScript when the recipient views the message. Exchange Online is not affected. Microsoft confirmed active exploitation when the vulnerability was disclosed in May 2026, and CISA added it to the Known Exploited Vulnerabilities catalog on May 15.

In July, the Russia-aligned threat actor TA488, also tracked as Laundry Bear and Void Blizzard, exploited the vulnerability in campaigns targeting government entities and organizations in the telecommunications, finance, hospitality, and aerospace sectors across the United States and Europe. The emails contained no malicious links or attachments. Opening the message in OWA was sufficient to trigger the exploit and execute a browser-resident JavaScript implant called OWAReaper.

OWAReaper operates within the authenticated OWA session and establishes multiple persistence paths. It stores an encrypted copy of itself in OWA browser settings, attempts to collect autofilled credentials and OAuth tokens, and modifies Exchange folder permissions to grant the built-in Default identity owner-level mailbox access. The server-side permission change can preserve access after password rotation or endpoint re-imaging. The implant can receive commands through GitHub commit messages or specially crafted emails and exfiltrate data over HTTPS or DNS tunneling.

Organizations should install the June 2026 Exchange Server security update or later. Response should also include auditing and removing unexpected mailbox permissions assigned to Default, revoking relevant Exchange Web Services tokens, clearing affected OWA local storage and IndexedDB data, and reviewing outbound HTTPS and DNS activity associated with the implant. Patching the server alone may not remove persistence already established through mailbox permissions or cached browser data.

Microsoft Office CVE-2018-0802: Cloud Atlas Continues to Exploit Legacy Equation Editor RCE

CVE-2018-0802 is a memory corruption vulnerability in the Microsoft Office Equation Editor component. An attacker can embed a crafted Equation Editor object in a malicious Office document and execute code in the current user’s context when the recipient opens the file. 

Cloud Atlas continues to use CVE-2018-0802 in targeted phishing operations. Recent campaigns delivered malicious Office documents that retrieved remote RTF templates containing the exploit, which then downloaded and executed additional malware. The resulting infection chains have deployed VBShower, VBCloud, PowerShower, and Cloud Atlas malware for reconnaissance, credential theft, file collection, and command execution. More recent activity also introduced PowerCloud and used reverse SSH tunnels, proxy tooling, and Tor to maintain alternate access channels.

The vulnerability requires a user to open a malicious document, but its continued use demonstrates that older Office exploit chains remain effective against unpatched and unsupported installations. Organizations should verify that the relevant Microsoft security updates are deployed, replace Office versions that no longer receive security fixes, and strengthen controls around externally received Office and RTF documents. Detection should focus on Equation Editor or Office processes launching PowerShell, mshta.exe, script interpreters, or unexpected network connections after a document is opened.

Dysphoria Botnet Combines Weak Credentials with Multi-CVE IoT Propagation

Dysphoria is an emerging botnet targeting routers, gateways, IP cameras, and other embedded Linux devices. Its propagation combines Telnet and SSH weak-credential attacks with a broad set of known remote code execution vulnerabilities. The observed exploit set includes legacy flaws such as CVE-2017-17215 and CVE-2020-8515, as well as newer vulnerabilities affecting multiple device brands and product families.

CVE-2020-8515 is an unauthenticated command injection vulnerability affecting the DrayTek Vigor2960, Vigor3900, and Vigor300B devices. Improper handling of shell metacharacters in requests to cgi-bin/mainfunction.cgi allows attackers to execute commands with root privileges. Within Dysphoria’s propagation model, however, the DrayTek flaw represents only one component of a wider exploit set.

Compromised systems are used for DDoS operations and as relay or proxy nodes. Recent variants use Ethereum and Solana naming services to retrieve infrastructure information and route command-and-control traffic through other compromised hosts. A dedicated relay variant also uses UPnP to map ports and convert infected systems into externally reachable traffic relays.

Organizations should replace unsupported network and IoT devices, remove unnecessary internet exposure, disable unused Telnet and SSH services, enforce strong administrative credentials, and patch known device-level RCE vulnerabilities. Detection should cover unexpected services, unusual UPnP mappings, outbound connections to blockchain-resolved infrastructure, and devices operating as unexplained traffic relays.

What Security Teams Should Prioritize

This week’s highest-priority exposures are concentrated in systems whose compromise can provide access beyond the vulnerable host.

  • Prioritize management and remote-access infrastructure. N-able N-central, SonicWall SMA1000, and Cisco FMC can expose managed endpoints, internal networks, credentials, security policy, and connected systems. Apply the available updates and restrict administrative interfaces to trusted networks.
  • Extend compromise assessments into downstream environments. Investigate endpoints reached through N-central remote-control functions, internal activity originating from SonicWall appliances, and reconnaissance or administrative actions associated with compromised firewall management platforms.
  • Address persistence independently of patching. Remove unauthorized tunnels and services, rotate affected credentials and authentication tokens, audit Exchange mailbox permissions, clear browser-resident OWA data, and re-image appliances where system integrity cannot be established.
  • Reduce reliance on unsupported technology. Continued exploitation of CVE-2018-0802 and CVE-2020-8515 highlights the operational risk created by legacy Office installations, routers, and embedded devices that no longer receive reliable security updates.
  • Validate the resulting exposure state. Confirm that affected versions are no longer deployed, vulnerable services are not externally reachable, relevant indicators are absent, and compensating controls effectively restrict the potential attack path.

SAFE CTEM operationalizes this approach across the exposure lifecycle. It creates a unified, deduplicated exposure inventory, prioritizes findings based on exploitability, threat intelligence, business impact, and compensating controls, and validates which exposures are reachable and exploitable. Prioritized exposures can then be mobilized through agentic workflows for ownership routing, ticketing, patch jobs, and governed exceptions. SAFE tracks changes in exposure state and risk over time, providing evidence of measurable risk reduction rather than treating vulnerability counts or ticket closure as the outcome.