securityaffairs.com 8/4/2026, 11:28:49 AM · external

CISA warns of active N‑central flaw CVE-2026-18577, urges patch

CISA warns of active N‑central flaw CVE-2026-18577, urges patch
Developing story breach 9 articles tracked
N‑able N‑central authentication bypass flaw (CVE-2026-18577) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the N-able N-central flaw, CVE-2026-18577, with a CVSS score of 8.2, to its Known Exploited Vulnerabilities catalog. This authentication bypass flaw originated from an incomplete fix of a previous vulnerability (CVE-2026-18556) and allows remote attackers to gain administrative access to vulnerable N-central servers. Affected customers should upgrade to version 2026.3.1.7.

Some organizations have been targeted, although exploitation is not widespread. Indicators of compromise include specific IP addresses and suspicious files on systems. Huntress reported ongoing attacks exploiting this vulnerability, emphasizing the need for patching, as over 55% of reachable N-central servers remain unpatched. CISA has mandated that federal agencies address this vulnerability by August 6, 2026.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline