CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
Summary
CISA has added a critical vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog. This flaw, tracked as CVE-2026-18577 with a CVSS score of 8.2, is a consequence of incomplete patching for a related vulnerability, CVE-2026-18556.
IFF Assessment
The inclusion of this vulnerability in the KEV catalog indicates active exploitation, posing a direct threat to organizations using the affected N-able N-central software.
Severity
The CVSS score of 8.2 reflects a high severity, likely due to factors such as an easily exploitable attack vector and significant impact on confidentiality, integrity, and availability.
CISA KEV: Listed as actively exploited. Federal patch due: August 06, 2026. Known ransomware use: Unknown.
Defender Context
Defenders should prioritize patching or implementing mitigation strategies for CVE-2026-18577, as it is actively being exploited. The fact that it's a result of incomplete patching highlights the importance of thorough vulnerability management and verification processes.