www.rapid7.com 8/4/2026, 12:31:39 PM · external

N-able patches CVE-2026-18577 auth bypass after exploits

N-able patches CVE-2026-18577 auth bypass after exploits
Developing story breach 9 articles tracked
N‑able N‑central authentication bypass flaw (CVE-2026-18577) exploited in the wild
CyberSIXT Evidence Panel
Primary Source status.n-able.com
CISA KEV Listed in KEV
Patch Patch Available

ON August 2, 2026, N-able disclosed CVE-2026-18577, an authentication bypass vulnerability in their N-central platform, allowing remote unauthenticated attackers administrative access to servers. This flaw was exploited in the wild, leveraging features like Take Control and Cloudflare Tunnel for persistent access. Organizations should urgently remediate the issue if running affected versions, with automated upgrades for hosted environments and manual remediation for on-premise ones.

The fixed version is N-central 2026.3.1 Hotfix 1. N-able provided indicators of compromise (IOCs) for investigation, including suspicious network activity and service presence, and advised contacting support if compromises are detected.

View Primary Source Via www.rapid7.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline