CVE Tools
Back to feed
Exploited in the wild N-central rce N-able auth-bypass

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Rapid7 Blog·By Rapid7··2 min read
CVE Tools coverage

A critical authentication bypass flaw in N-able N-central, tracked as CVE-2026-18577, has been actively exploited in real-world attacks since August 1, 2026. This vulnerability affects all versions of the software up to 2026.3.1 and allows attackers to bypass login controls and take full administrative control of affected systems. The flaw was discovered following an incomplete fix for a related vulnerability, CVE-2026-18556. Successful exploitation has led to attackers using N-central’s Take Control feature to access managed endpoints and deploying Cloudflare Tunnel (cloudflared) to maintain persistent access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerability (KEV) catalog on August 3, 2026. N-able has released a hotfix—version 2026.3.1 Hotfix 1—to address the issue.

Overview

On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.…

Continue reading on Rapid7 Blog