CVE Tools

CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild

Rapid7 BlogBy Rapid72 min read

Reported exploitedN-central

Our summary

A critical authentication bypass flaw in N-able N-central, tracked as CVE-2026-18577, has been actively exploited in real-world attacks since August 1, 2026. This vulnerability affects all versions of the software up to 2026.3.1 and allows attackers to bypass login controls and take full administrative control of affected systems. The flaw was discovered following an incomplete fix for a related vulnerability, CVE-2026-18556. Successful exploitation has led to attackers using N-central’s Take Control feature to access managed endpoints and deploying Cloudflare Tunnel (cloudflared) to maintain persistent access. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added this vulnerability to its Known Exploited Vulnerability (KEV) catalog on August 3, 2026. N-able has released a hotfix—version 2026.3.1 Hotfix 1—to address the issue.

Read at Rapid7 Blog

Below is the opening; the full story is at Rapid7 Blog.

From Rapid7 Blog

Overview

On August 2, 2026, N-able published a security advisory for CVE-2026-18577, an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.…

Continue at Rapid7 Blog

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store