Skip to content
CC-4823 - Active Exploitation of Critical N

CC-4823 - Active Exploitation of Critical N

Digital.Nhs.Uk [email protected] (NHS Digital) August 3, 2026

Exploitation of CVE-2026-18577 could allow an attacker to bypass authentication and lead to administrative account takeover

Exploitation of CVE-2026-18577 could allow an attacker to bypass authentication and lead to administrative account takeover

The following platforms are known to be affected:

Exploitation of CVE-2026-18577

N-able has observed exploitation of CVE-2026-18577, leading to account takeover and full administrative access to the N-central server.

The NHS England National CSOC assesses further exploitation as likely.

N-able has released a security update for N-central to address an incomplete patch for CVE-2026-18556; this issue has been assigned CVE-2026-18577.

Affected organisations are strongly encouraged to review N‑central Security Update – August 2, 2026 and apply the relevant update as soon as possible.

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Last edited: 3 August 2026 12:17 pm

Extracted Entities

Attack Types (1)

Companies (1)

Platforms (1)

Tools (1)