AllCyberNews

CVE-2026-18577

Incomplete patch leads to administrative account takeover

CVSS 8.2 high · N-able N-central · published 2026-08-02

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Coverage 3 sources

  1. 2026-08-03 CISA Cybersecurity Advisories high CISA Adds One Known Exploited Vulnerability to Catalog

    CISA added CVE-2026-18577, an N-able N-central auth bypass vuln, to its Known Exploited Vulnerabilities Catalog.

  2. 2026-08-03 Help Net Security high Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)

    Attackers exploit N-able N-central flaw to access managed endpoints.

  3. 2026-08-10 Help Net Security high N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

    N-able releases second hotfix for N-central to address ongoing exploitation of CVE-2026-18577.

  4. 2026-08-10 GovInfoSecurity high China-Linked Hackers Exploit N-able Flaw in Ransomware Attacks

    China-linked hackers exploit N-able flaw in ransomware attacks.

Also covered