CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
A critical authentication bypass flaw in N-able N-central, tracked as CVE-2026-18577, has been actively exploited in real-world attacks since August 1, 2026. This vulnerability affects all versions of the software up to 2026.3.1 and allows attackers to bypass login controls and take full administrative control of affected systems. The flaw was discovered following an incomplete fix for a related vulnerability, CVE-2026-18556. Successful exploitation has led to attackers using N-central’s Take Control feature to access managed endpoints and deploying Cloudflare Tunnel (cloudflared) to maintain persistent access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerability (KEV) catalog on August 3, 2026. N-able has released a hotfix—version 2026.3.1 Hotfix 1—to address the issue.
Overview
On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.…