Fixing and finding

[Jump to remediation plan](#remediation)

CVE ID

# CVE-2026-18577

Published 2026-08-02

Updated 2 months ago

Vendor/s

N-able

Product/s

N-central

Version/s

\* > 2026.3

KEV Status

Active Exploitation

Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.

CVSS Score (v3.1)

8.1

/ 10

High

Severity Details

Base score

8.1 High

Attack vector

Network

Attack complexity

High

Privileges required

None

User interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

High

Availability

High

Table of Contents

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

[Description ](#description)[Why this matters ](#why-this-matters)[CPE ](#cpe)[Related weakness (CWE) ](#cwe)[Remediation plan ](#remediation)[Detection Guidance ](#detection-guidance)[References ](#references)[Sources](#sources)

## Description

CVE-2026-18577 is a high-severity authentication bypass in N-able N-central (versions <= 2026.3.1) being actively exploited in the wild.

## Why this matters

"CVE-2026-18577 is a high-severity security flaw in N-able N-central that allows remote attackers to bypass authentication and achieve full account takeover. With a CVSS score of 8.1, this vulnerability is particularly dangerous because it represents an incomplete fix for a previous flaw, CVE-2026-18556. Its inclusion in CISA’s Known Exploited Vulnerabilities (KEV) catalog confirms that threat actors are actively leveraging this weakness in the wild. For MSPs and IT departments using N-central to manage client infrastructure, an unpatched instance could lead to widespread compromise across multiple downstream environments, making immediate remediation a top priority."

## CPE

N-able

| Product   | Version Start | Version End (excl.) | Status     |
| --------- | ------------- | ------------------- | ---------- |
| n-central | \*            | 2026.3              | vulnerable |
| n-central | 2026.3        | 2026.3              | vulnerable |

## Related weakness (CWE)

CWE-288

## Remediation plan

1

### Apply official patches

Immediately apply N-central 2026.3 Hotfix 1 or the latest available security update provided by N-able to address the authentication bypass logic.

2

### Update affected systems

Verify that all N-central instances running versions up to and including 2026.3.1 are upgraded to a patched version to ensure the incomplete fix from CVE-2026-18556 is resolved.

3

### Restrict access

Limit exposure by placing N-central management interfaces behind a VPN or restricting access to known-good IP addresses to prevent unauthorized network-based exploitation.

4

### Monitor for exploitation

Follow CISA’s Forensics Triage Requirements to scan for indicators of compromise and review audit logs for unauthorized administrative account activity or unusual login patterns.

## Detection Guidance

"Security teams should monitor N-central access logs for successful logins that bypass standard authentication flows or MFA. Look for unauthorized administrative account creation or modifications. Inspect web server logs for unusual requests to authentication endpoints that deviate from normal user behavior. Organizations should also implement network signatures to detect exploitation attempts targeting the N-central management interface, specifically focusing on patterns associated with known authentication bypass techniques."

## References

[https://documentation.n-able.com/N-central/Release\_Notes/GA/Content/N-central\_2026.3\_HF1\_Release\_Notes.htm Patch Release Notes ](https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm)[https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ Release Notes ](https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/)[https://www.cve.org/CVERecord?id=CVE-2026-18556 VDB Entry ](https://www.cve.org/CVERecord?id=CVE-2026-18556)[https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field\_cve=CVE-2026-18577 US Government Resource ](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577)[https://www.n-able.com/blog/n-central-security-update-august-2-2026 Vendor Advisory](https://www.n-able.com/blog/n-central-security-update-august-2-2026)

## Sources

NIST National Vulnerability Database (NVD)

CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](https://www.upguard.com/contact-sales)

[Free trial](https://www.upguard.com/demo)
