CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

Summary

N-able N-central has an authentication bypass vulnerability (CVE-2026-18577) that allows for account takeover. This flaw stems from an incomplete patch for a previous vulnerability, CVE-2026-18556. Organizations are advised to apply vendor-provided mitigations and adhere to CISA's directives on prioritizing security updates.

IFF Assessment

FOE

The vulnerability allows for authentication bypass and account takeover, which is a significant risk to defenders.

Severity

9.8 Critical (AI Estimated)

The vulnerability allows for authentication bypass and account takeover, which indicates a critical impact. The attack vector is likely network-based, and exploitability could be high given it's a bypass flaw.

CISA KEV: Listed as actively exploited. Federal patch due: August 06, 2026. Known ransomware use: Unknown.

Defender Context

This vulnerability in N-able N-central presents a critical risk as it allows for authentication bypass and subsequent account takeover. Defenders must prioritize applying the vendor's mitigations swiftly, especially considering it's a regression from a previous patch. The known ransomware use is unknown, but such vulnerabilities are often exploited in real-world attacks.

Read Full Story →