CISA added CVE-2026-18577 to the Known Exploited Vulnerabilities catalog on August 3, 2026; an authentication bypass in N-able N-central that stems from an incomplete patch for CVE-2026-18556 and is already under active exploitation.
What Is It
CVE-2026-18577 is an authentication bypass using an alternate path or channel (CWE-288) in N-able N-central. Per the NVD record, an incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central versions through 2026.3.1.
The vulnerability carries a CVSS 4.0 base score of 8.2 (HIGH), vector CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A. It is network-accessible with no privileges and no user interaction required, though attack complexity is rated HIGH. The CVSS exploit maturity metric is set to ATTACKED.
Why It Matters
CISA's KEV listing confirms active exploitation. CISA's SSVC decision points for this CVE record exploitation as "active," automatable as "no," and technical impact as "partial." Known ransomware campaign use is listed as Unknown.
The outcome described in the source data is account takeover; direct access to accounts on an N-central instance. The vulnerability existing because a prior fix was incomplete means organizations that patched CVE-2026-18556 and considered the issue closed may still be exposed.
What's Vulnerable
- Vendor/Product: N-able N-central
- Affected: all versions through 2026.3.1
- Fixed in: 2026.3.1.7 (shipped as N-central 2026.3 Hotfix 1)
Patch Status
N-able published N-central 2026.3 Hotfix 1 as mitigation, documented in the vendor release notes and a status-page advisory dated August 2, 2026.
CISA's required action, with a due date of August 6, 2026: apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 "Prioritizing Security Updates Based on Risk" guidance and CISA's "Forensics Triage Requirements." Follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines.
Sources
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577
- NVD, CVE-2026-18577, https://nvd.nist.gov/vuln/detail/CVE-2026-18577
- N-able, N-central 2026.3 HF1 Release Notes, https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm
- N-able Status, Hotfix 1 mitigation for CVE-2026-18577, https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
- CVE.org, CVE-2026-18556 (original vulnerability), https://www.cve.org/CVERecord?id=CVE-2026-18556
- CISA BOD 26-04; https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance; https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk