CISA Adds One Known Exploited Vulnerability to Catalog

Summary

CISA has added CVE-2026-18577, an authentication bypass vulnerability in N-able N-central, to its Known Exploited Vulnerabilities (KEV) Catalog due to evidence of active exploitation. This addition reinforces the importance of CISA's Binding Operational Directive (BOD) 26-04, which mandates federal agencies prioritize patching vulnerabilities listed in the KEV Catalog, especially those that grant total control after exploitation.

IFF Assessment

FOE

The addition of a new exploited vulnerability to CISA's KEV catalog indicates a new active threat that defenders must address, posing a risk to systems.

Severity

9.0 Critical (AI Estimated)

An authentication bypass vulnerability allowing for total control of an asset post-exploitation is highly critical, hence the high CVSS score reflecting significant attack complexity and impact.

CISA KEV: Listed as actively exploited. Federal patch due: August 06, 2026. Known ransomware use: Unknown.

Defender Context

Defenders must be aware of CVE-2026-18577 and prioritize its remediation on N-able N-central systems, especially within federal agencies subject to BOD 26-04. The inclusion of this vulnerability in CISA's KEV Catalog highlights the ongoing risk posed by actively exploited flaws and the need for robust vulnerability management programs.

Read Full Story →