Vulnerability record · CVE-2026-18577 · published 2 August 2026
CVE-2026-18577: N-able N-central incomplete patch enables auth bypass and account takeover
N Able · N Central
An incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the original flaw was only partially patched, systems believed to be remediated remain exposed to account takeover. The vendor has issued a hotfix (2026.3 HF1) and CISA added the issue to KEV the day after publication.
Description
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityIt is in CISA KEV with a near-term remediation deadline, has a very high EPSS score, and allows unauthenticated account takeover on an internet-facing management platform.
What it is
An incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the original flaw was only partially patched, systems believed to be remediated remain exposed to account takeover. The vendor has issued a hotfix (2026.3 HF1) and CISA added the issue to KEV the day after publication.
Impact
An unauthenticated remote attacker can bypass authentication and take over accounts, gaining the privileges of the compromised account. The CVSS 4.0 vector shows high confidentiality impact with limited scope change, so data exposure is the primary consequence.
Attack surface
Reachable over the network (AV:N) with no privileges and no user interaction required (PR:N/UI:N), consistent with CWE-288 alternate-path authentication bypass. Attack complexity is rated high (AC:H), so some conditions or knowledge of the alternate path are needed.
Exploitation
CISA added it to KEV on 2026-08-03 with a remediation due date of 2026-08-06, indicating known exploitation. EPSS is 0.54068 (98.9th percentile), and no ransomware campaign use is documented.
What to do
- Apply the N-central 2026.3 Hotfix 1 (HF1) update immediately per the vendor release notes and status advisory.
- If patching cannot be completed before the CISA due date, follow BOD 26-04 guidance for cloud services or discontinue use of the product.
- Restrict internet exposure of N-central management interfaces to trusted networks or VPN while remediation is pending.
- Audit and rotate credentials for accounts on affected N-central instances, and review for unauthorized account changes.
- Confirm the prior CVE-2026-18556 fix is fully applied, since this issue is an incomplete patch of that flaw.
Detection
- Review N-central authentication and access logs for logins or session activity that bypass normal credential flows, especially from unexpected source IPs.
- Hunt for new or modified administrative accounts and permission changes on N-central instances around and after 2026-08-02.
- Monitor for access to alternate paths or endpoints outside normal N-central authentication routes.
- Correlate N-central logs with downstream managed-endpoint activity for signs of lateral movement or credential reuse.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2026-18577 to the Known Exploited Vulnerabilities catalog on 3 August 2026 as "N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability". Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. Federal deadline 6 August 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2026-18577 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-18577), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.