CVE Tools
Back to feed
Exploited in the wild N-able N-central supply-chain N-able zero-day

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed a critical, actively exploited vulnerability in N-able N-central within its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-18577 (CVSS score: 8.2), enables remote attackers to bypass authentication and take over accounts. It affects versions prior to 2026.3 HF1. Successful attacks could lead to unauthorized server access and lateral movement into connected systems. N-able has issued a fix, urging administrators to update immediately to prevent potential breaches.