Skip to content
Active Exploitation of N-able N-central Authentication Bypass Vulnerability

Active Exploitation of N-able N-central Authentication Bypass Vulnerability

First seen 5 Aug 2026, 06:31 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 5, 2026 at 23:54 UTC
  • CVE-2026-18577 allows unauthenticated remote access to N-central servers.
  • Attackers exploited the vulnerability before a patch was available, targeting high-value systems.
  • CISA added the vulnerability to its KEV catalog, highlighting its active exploitation.

N-able has issued an emergency hotfix for CVE-2026-18577, an authentication bypass vulnerability in its N-central RMM platform, which allows remote, unauthenticated attackers to gain administrative access. This flaw affects all versions prior to 2026.3.1.7 and was actively exploited before the fix was released. Attackers utilized the platform's Take Control feature to access managed endpoints and deployed Cloudflare Tunnel services for persistent access. The Cybersecurity and Infrastructure Security Agency (CISA) added the vulnerability to its Known Exploited Vulnerabilities catalog on August 3, 2026. N-able previously addressed a related vulnerability, CVE-2026-18556, but the fix did not prevent this new exploitation path. The vendor has not disclosed specific technical details about the attack vector or the vulnerable endpoint. The situation poses an immediate operational risk to managed service providers and enterprise IT teams using N-central.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 47d ago How this analysis works

Timeline

2026-08-01
CVE-2026-18556 published
N-able disclosed an earlier authentication bypass vulnerability affecting N-central.
Socprime
2026-08-02
CVE-2026-18577 published
N-able released a hotfix for the newly identified authentication bypass vulnerability in N-central.
Fieldeffect
2026-08-03
CISA adds CVE-2026-18577 to KEV catalog
CISA confirmed active exploitation of the vulnerability, marking it as a significant threat.
Fieldeffect
2026-08-04
First public PoC for CVE-2026-18577
Publicly available proof of concept for the authentication bypass vulnerability was released.
Socprime

More articles in this cluster (12)

Following this threat?

Track CISA and CVE-2026-18556 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed