Active Exploitation of N-able N-central Authentication Bypass Vulnerability

Active Exploitation of N-able N-central Authentication Bypass Vulnerability

First seen 5 Aug 2026, 06:31 UTC SocprimeFieldeffect 82% similarity 74.0

Article Content

Browse articles
ThreatCluster

N-able has issued an emergency hotfix for CVE-2026-18577, an authentication bypass vulnerability in its N-central RMM platform, which allows remote, unauthenticated attackers to gain administrative access. This flaw affects all versions prior to 2026.3.1.7 and was actively exploited before the fix was released. Attackers utilized the platform's Take Control feature to access managed endpoints and deployed Cloudflare Tunnel services for persistent access. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog on August 3, 2026. N-able previously addressed a related vulnerability, CVE-2026-18556, but the fix did not prevent this new exploitation path. The vendor has not disclosed specific technical details about the attack vector or the vulnerable endpoint. The situation poses an immediate operational risk to managed service providers and enterprise IT teams using N-central.

Key Points: • CVE-2026-18577 allows unauthenticated remote access to N-central servers. • Attackers exploited the vulnerability before a patch was available, targeting high-value systems. • CISA added the vulnerability to its KEV catalog, highlighting its active exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-01
CVE-2026-18556 published
N-able disclosed an earlier authentication bypass vulnerability affecting N-central.
Socprime
2026-08-02
CVE-2026-18577 published
N-able released a hotfix for the newly identified authentication bypass vulnerability in N-central.
Fieldeffect
2026-08-03
CISA adds CVE-2026-18577 to KEV catalog
CISA confirmed active exploitation of the vulnerability, marking it as a significant threat.
Fieldeffect
2026-08-04
First public PoC for CVE-2026-18577
Publicly available proof of concept for the authentication bypass vulnerability was released.
Socprime

Community

Browse all →

Tracked Entities in This Story