Our takeCISA added CVE-2026-18577 to its KEV catalog: this incomplete fix for an N-able N-central auth bypass is confirmed exploited in the wild. Update to 2026.3.1.7 or later.Cyber Resilience desk
Sources (4)
- hackernews · hackernews
- cisa_advisories · cisa_advisories
- rapid7 · rapid7
- hackernews · hackernews
What this means for you — Security leader:CISA added CVE-2026-18577 in N-able N-central to KEV after confirmed customer compromises. Update to version 2026.3.1.7 or later immediately.
What this means for you — Lean IT orgs:If you use N-able N-central to manage devices, update it to version 2026.3.1.7 or later right away. Attackers are actively exploiting this flaw.
What this means for you — MSP:N-able N-central customers: push version 2026.3.1.7 or later across all instances. CISA confirmed active exploitation leading to customer compromises.
What this means for you — Researcher:CVE-2026-18577 is an incomplete fix for CVE-2026-18556 in N-able N-central; CISA added it to KEV after in-the-wild customer compromises.