CISA has added CVE‑2026‑18577 to its Known Exploited Vulnerabilities catalogue. The flaw affects N‑able’s N‑central platform and is named the N‑able N‑central Authentication Bypass Using an Alternate Path or Channel Vulnerability. It allows an attacker to bypass authentication and gain account takeover by exploiting an incomplete patch for CVE‑2026‑18556.
The vulnerability is an authentication bypass that can be triggered via a specially crafted request to an alternate channel in N‑central. Successful exploitation enables an attacker to assume the privileges of any legitimate user, leading to potential data theft, lateral movement or further compromise. NVD rates the issue CVSS 8.2 (High). A patch is available in N‑central 2026.3 Hotfix 1, as documented in the vendor’s release notes.
Because the entry appears in the KEV catalogue, active exploitation in the wild has been confirmed. The flaw was added to the KEV catalogue on 2026‑08‑03 after confirmation of active exploitation. CISA has not linked this flaw to any known ransomware campaign. Federal civilian executive branch agencies must apply the required mitigations by 2026‑08‑06, the remediation deadline set by CISA.
CISA directs affected organisations to apply mitigations in accordance with vendor instructions, ensuring compliance with BOD 26‑04 Prioritizing Security Updates Based on Risk and the accompanying Forensics Triage Requirements. For cloud‑based instances, follow the applicable BOD 26‑04 guidance or discontinue use of the product if mitigations cannot be applied. All stakeholders should assess each asset’s internet exposure and adhere to BOD 26‑04 patching guidelines.
For full technical details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-18577 and the CISA KEV catalogue.