CVE-2026-18577 · Critical · CISA KEV
N-able N-central Auth Bypass (CVE-2026-18577) Allows Account Takeover
Threat Engine Auto-Feed · data current as of 2026-08-04
CVE-2026-18577 in N-able N-central is an authentication bypass vulnerability, stemming from an incomplete patch for a prior CVE. This flaw allows for account takeover and is actively exploited in the wild, as confirmed by its inclusion in CISA KEV.
- CVSS:
- EPSS percentile: 0.83327
- Exploitation pressure: 75/100 (Critical)
Exploitation reality: listed in CISA KEV (exploited in the wild) · EPSS 83th percentile. Threat × Vulnerability from public signals — impact depends on your environment.
Weakness —
This vulnerability is an authentication bypass, meaning an attacker can circumvent security measures designed to verify user identity. By exploiting an 'alternate path or channel,' an attacker can gain unauthorized access to accounts without needing valid credentials.
Who's at risk
Exposure: unknown · Auth: unknown · unknown
Enterprise profiles most at risk
- Organizations using N-able N-central for IT management, particularly those in Financial services and Technology sectors due to observed adversary targeting.
- Enterprises with critical infrastructure managed by N-central.
Misconfigurations that escalate it
- Failure to apply the complete and correct patch for CVE-2026-18556, as this vulnerability is a direct result of an incomplete fix.
High-impact scenarios
- Complete account takeover within N-central, leading to unauthorized control over managed systems and data.
- Lateral movement and privilege escalation within the compromised environment.
- Potential for data exfiltration, service disruption, or deployment of further malicious payloads by financially motivated actors (FIN7, LockBit affiliates, APT38) or state-sponsored groups (APT29, Scattered Spider).
Likely adversaries
- FIN7 — Financial services (Assessed)
- LockBit affiliates — Financial services (Assessed)
- APT38 (Lazarus) — Financial services (Assessed)
- APT29 (Cozy Bear) — Technology (Assessed)
- Scattered Spider — Technology (Assessed)
What to do (defensive)
Detect
- Monitor N-able N-central logs for unusual authentication attempts or unauthorized access patterns.
- Look for unexpected changes to configurations or managed systems originating from N-central accounts.
- Implement robust endpoint detection and response (EDR) solutions on systems managed by N-central to detect post-exploitation activities.
Contain
- Isolate N-able N-central instances from critical network segments if compromise is suspected.
- Revoke and reset credentials for all N-central accounts, especially administrative ones, after patching.
- Implement multi-factor authentication (MFA) for all N-central access to mitigate the impact of potential account takeovers.
Patch
- Apply the latest security patches and updates provided by N-able for N-central immediately to address CVE-2026-18577.
- Verify that the patch for CVE-2026-18556 was completely and correctly applied.
Frontier verdict — Critical
This is a critical vulnerability due to active exploitation in the wild (CISA KEV), high EPSS percentile, and potential for full account takeover in N-able N-central.
For detection-engineering and awareness only · point-in-time · not security advice · sourced from NVD, FIRST EPSS, CISA KEV. Adversary mappings are assessments unless cited.