CVE-2026-18577
Incomplete patch leads to administrative account takeover
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Coverage 3 sources
-
2026-08-03
CISA Cybersecurity Advisories
high
CISA Adds One Known Exploited Vulnerability to Catalog
CISA added CVE-2026-18577, an N-able N-central auth bypass vuln, to its Known Exploited Vulnerabilities Catalog.
-
2026-08-03
Help Net Security
high
Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)
Attackers exploit N-able N-central flaw to access managed endpoints.
-
2026-08-10
Help Net Security
high
N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577
N-able releases second hotfix for N-central to address ongoing exploitation of CVE-2026-18577.
-
2026-08-10
GovInfoSecurity
high
China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks
China-linked hackers exploit N-able flaw in ransomware attacks.
Also covered
- CVE-2026-86950 Apple iOS and iPadOS
- CVE-2023-6548 Cloud Software Group NetScaler ADC
- CVE-2023-25608 Fortinet FortiAP-W2
- CVE-2026-88772 Memory overflow vulnerability leading to Remote Code Execution or Denial of Service
- CVE-2026-88771 A remote code execution vulnerability exists due to improper input validation, which can allow an unauthenticated attacker to execute arbitrary commands