www.darkreading.com 8/3/2026, 9:49:13 PM · external

Nable Ncentral CVE-2026-18577 lets attackers hijack admin access

Nable Ncentral CVE-2026-18577 lets attackers hijack admin access
CyberSIXT Evidence Panel
Primary Source n-able.com
CISA KEV Listed in KEV
Patch Patch Available

N-ABLE has identified a critical authentication bypass vulnerability, CVE-2026-18577, affecting its N-central remote monitoring and management platform. Attackers exploited this flaw to gain unauthorized administrator access to customer environments, enabling them to connect to internal systems and establish persistent access. Although the vulnerability was patched in version 2026.3.1.7, a significant percentage of self-hosted servers remain unpatched.

N-able recommends immediate upgrades for affected customers and cautions that exploitation continues in some cases. Despite the severity, confirmed exploitation appears limited to a small number of organizations.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline