Active Exploitation of N-able N-central Authentication Bypass Vulnerability
Article Content
- •CVE-2026-18577 allows unauthenticated remote access to N-central servers.
- •Attackers exploited the vulnerability before a patch was available, targeting high-value systems.
- •CISA added the vulnerability to its KEV catalog, highlighting its active exploitation.
N-able has issued an emergency hotfix for CVE-2026-18577, an authentication bypass vulnerability in its N-central RMM platform, which allows remote, unauthenticated attackers to gain administrative access. This flaw affects all versions prior to 2026.3.1.7 and was actively exploited before the fix was released. Attackers utilized the platform's Take Control feature to access managed endpoints and deployed Cloudflare Tunnel services for persistent access. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog on August 3, 2026. N-able previously addressed a related vulnerability, CVE-2026-18556, but the fix did not prevent this new exploitation path. The vendor has not disclosed specific technical details about the attack vector or the vulnerable endpoint. The situation poses an immediate operational risk to managed service providers and enterprise IT teams using N-central.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track CISA and CVE-2026-18556 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…