All incidents

N-able N-central authentication bypass exploited (CVE-2026-18577)

breachopenAug 3, 2026 — Aug 3, 2026
N-able N-central authentication bypass exploited (CVE-2026-18577)

N-ABLE has released a hotfix for CVE-2026-18577 after attackers exploited the flaw to gain unauthorized access to N-central servers, as reported by SecurityWeek. The vulnerability allowed remote actors to bypass authentication and obtain administrative rights on systems running versions prior to 2026.3.1.7. The issue was first observed on 3 August 2026 and prompted an urgent advisory from the vendor.

CVE-2026-18577 carries a CVSS score of 8.2 and stems from an insufficient validation of session tokens in the N-central web interface. Attackers could craft a specially formed request that tricks the application into accepting a forged token, thereby bypassing login checks. This flaw is related to an earlier issue, CVE-2026-18556, which was patched but left a residual vector that remained exploitable.

Versions of N-central older than 2026.3.1.7 are affected, including all 2026.3 releases and earlier branches. Once inside, adversaries can leverage the platform’s remote control features to execute commands on managed endpoints, deploy additional payloads or alter configurations. The exploit does not require any privileges beyond network reachability to the management portal.

Although N-able reports that only a limited subset of customers experienced impact, many organisations had not applied the available hotfix by the close of business on 3 August, according to The Hacker News. No specific threat actor has been linked to the campaign, but the timing coincides with a rise in automated scanning for exposed N-central instances. The continued exploitation of a patched problem highlights the danger of delayed update deployment.

The incident highlights how a seemingly resolved vulnerability can remain a risk when patch latency leaves windows open for attackers. Organisations that rely on N-central for managing large fleets of endpoints face potential exposure to credential theft, lateral movement and ransomware deployment if the flaw is not mitigated. Prompt remediation is therefore essential to prevent further compromise.

Defenders should immediately apply the hotfix released on 2 August 2026, which is available via the vendor’s status page. They should also review authentication logs for any successful logins from unfamiliar IP addresses or unusual timestamps that could indicate token abuse. Enforcing multi‑factor authentication on the N-central portal and restricting access to trusted networks can reduce the chance of successful token forgery.

Network segmentation that isolates the management server from untrusted zones limits the reach of an attacker who might bypass authentication. Finally, maintaining an up‑to‑date asset inventory and enabling alerts for missing patches ensures that similar gaps are caught before they are exploited.

Intelligence briefing updated Aug 3, 2026

CVE-2026-18556 8.2 CVE-2026-18577 8.2
Root sourcestatus.n-able.com
Timeline Coverage

Swipe to explore timeline