CVE-2026-18577
Incomplete patch leads to administrative account takeover
Description
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
In plain language
AI Act nowCVE-2026-18577 is an authentication-bypass problem in N-able n-central that can let attackers take over the administrative account remotely; if you use n-central, you should act immediately because it is being exploited in the wild.
CVE-2026-18577 is a remote authentication-bypass/admin account takeover issue in N-able n-central caused by an incomplete patch for CVE-2026-18556, enabling attackers to bypass authentication and gain administrative control without user interaction.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
References
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flawen·The Hacker News· Exploited N-central rce
- Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayen-us·Help Net Security· Exploited Salesforce data-breach
- N-able выпустила уже два патча для уязвимости обхода аутентификации в N-centralru-ru·Хакер (xakep.ru)· Exploited N-central auth-bypass
- New StormEncryptor ransomware used by former Medusa affiliateen-us·BleepingComputer· Exploited StormEncryptor Storm-1175
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawen·The Hacker News· Exploited StormEncryptor Storm-1175
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsen·The Hacker News· Exploited Mythos 5 UNC6671
- N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577en-us·Help Net Security·
- Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026en-us·Help Net Security· Roundup web-app
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persisten·The Hacker News· Exploited N-able N-central privilege-escalation
- CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilitiesen-us·SecurityWeek· Exploited Langflow web-app
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-18577 and every CVE in our database. Create a free account — no credit card required.
Create Free Account