๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Summary
N-able N-central has a security flaw that allows attackers to bypass authentication (the process of verifying a user's identity) and take over accounts by using an alternate path or channel to access the system. This vulnerability exists because an earlier patch for a related issue, CVE-2026-18556, was incomplete. The flaw is currently being exploited by attackers in real-world attacks.
Solution / Mitigation
Apply mitigations according to N-able's vendor instructions while following CISA's BOD 26-04 guidance on prioritizing security updates. For cloud services, follow BOD 26-04 guidance or stop using the product if mitigations are unavailable. The specific fix is N-central version 2026.3 HF1 (hotfix 1), which addresses this vulnerability.
Vulnerability Details
EPSS: 1.5%
Yes
๐ฅ Actively Exploited
August 2, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18577
First tracked: August 3, 2026 at 08:01 PM
Classified by LLM (prompt v3) ยท confidence: 95%