THE Known Exploited Vulnerabilities (KEV) Catalog, maintained by CISA, serves as an authoritative resource for cybersecurity professionals to manage vulnerabilities that are actively exploited in the wild. The catalog aims to help organizations prioritize their vulnerability management. The current entry details CVE-2026-18577, a vulnerability in N-able N-central that allows for authentication bypass and potential account takeover.
The vulnerability was attributed to an incomplete patch for a prior vulnerability, CVE-2026-18556, and stakeholders are advised to apply mitigations per vendor instructions and follow CISA’s guidance on security updates. The catalog is accessible in several formats, including CSV and JSON.