Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-18577

Published 2026-08-02
Updated last month
Vendor/s
N-able
Product/s
N-central
Version/s
* > 2026.3
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
8.1
/ 10
High
Severity Details
Base score
8.1 High
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Description

CVE-2026-18577 is a high-severity authentication bypass in N-able N-central (versions <= 2026.3.1) being actively exploited in the wild.

CPE

N-able logo
N-able
Product Version Start Version End (excl.) Status
n-central * 2026.3 vulnerable
n-central 2026.3 2026.3 vulnerable

Related weakness (CWE)

CWE-288

Remediation plan

1

Apply official patches

Immediately apply N-central 2026.3 Hotfix 1 or the latest available security update provided by N-able to address the authentication bypass logic.

2

Update affected systems

Verify that all N-central instances running versions up to and including 2026.3.1 are upgraded to a patched version to ensure the incomplete fix from CVE-2026-18556 is resolved.

3

Restrict access

Limit exposure by placing N-central management interfaces behind a VPN or restricting access to known-good IP addresses to prevent unauthorized network-based exploitation.

4

Monitor for exploitation

Follow CISA’s Forensics Triage Requirements to scan for indicators of compromise and review audit logs for unauthorized administrative account activity or unusual login patterns.

Detection Guidance

"Security teams should monitor N-central access logs for successful logins that bypass standard authentication flows or MFA. Look for unauthorized administrative account creation or modifications. Inspect web server logs for unusual requests to authentication endpoints that deviate from normal user behavior. Organizations should also implement network signatures to detect exploitation attempts targeting the N-central management interface, specifically focusing on patterns associated with known authentication bypass techniques."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management