CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2026-08-03. EPSS: 14.6% chance of exploitation in the next 30 days.
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Affected products
- N-able N-central: before 2026.3 (fixed in 2026.3); version 2026.3 only
Published 2026-08-02. Last modified 2026-08-04.