CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Summary
N-able N-central has an authentication bypass vulnerability (CVE-2026-18577) that allows for account takeover. This flaw stems from an incomplete patch for a previous vulnerability, CVE-2026-18556. Organizations are advised to apply vendor-provided mitigations and adhere to CISA's directives on prioritizing security updates.
IFF Assessment
The vulnerability allows for authentication bypass and account takeover, which is a significant risk to defenders.
Severity
The vulnerability allows for authentication bypass and account takeover, which indicates a critical impact. The attack vector is likely network-based, and exploitability could be high given it's a bypass flaw.
CISA KEV: Listed as actively exploited. Federal patch due: August 06, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in N-able N-central presents a critical risk as it allows for authentication bypass and subsequent account takeover. Defenders must prioritize applying the vendor's mitigations swiftly, especially considering it's a regression from a previous patch. The known ransomware use is unknown, but such vulnerabilities are often exploited in real-world attacks.