CVE Tools

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The Hacker NewsBy The Hacker News

Reported exploitedN-able N-central

Our summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has listed a critical, actively exploited vulnerability in N-able N-central within its Known Exploited Vulnerabilities catalog. The flaw, CVE-2026-18577 (CVSS score: 8.2), enables remote attackers to bypass authentication and take over accounts. It affects versions prior to 2026.3 HF1. Successful attacks could lead to unauthorized server access and lateral movement into connected systems. N-able has issued a fix, urging administrators to update immediately to prevent potential breaches.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store