Skip to content
Actively exploited

CVE-2026-18577Authentication Bypass in N-able N-central

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

View on NVD

Analysis

N-able N-central permite la omisión de autenticación y la toma de control de cuentas debido a un parche incompleto de una vulnerabilidad previa. El fallo está siendo explotado activamente en ataques reales para comprometer herramientas de gestión remota de infraestructura. Es fundamental actualizar a versiones superiores a la 2026.3.1 para mitigar el riesgo de acceso no autorizado.

Relevant roles

CyberSecurityCloudLinuxWindowsBackend

Severity

N/A

CISA KEV

Added to KEV: 2026-08-03
Federal patch deadline: 2026-08-06
Known ransomware use: Unknown
Required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

EPSS

Probability of exploitation (next 30 days): 0.0148 (1.5%)
Percentile: 71.3%
EPSS: 2026-08-03

Technical description

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Published: 8/2/2026, 11:16:26 PM
Last modified: 8/3/2026, 8:17:15 PM

References

HomeEventsBlogResourcesCoursesTeam