THE U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the N-able N-central flaw, CVE-2026-18577, with a CVSS score of 8.2, to its Known Exploited Vulnerabilities catalog. This authentication bypass flaw originated from an incomplete fix of a previous vulnerability (CVE-2026-18556) and allows remote attackers to gain administrative access to vulnerable N-central servers. Affected customers should upgrade to version 2026.3.1.7.
Some organizations have been targeted, although exploitation is not widespread. Indicators of compromise include specific IP addresses and suspicious files on systems. Huntress reported ongoing attacks exploiting this vulnerability, emphasizing the need for patching, as over 55% of reachable N-central servers remain unpatched. CISA has mandated that federal agencies address this vulnerability by August 6, 2026.