LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 3, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 6, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog on Aug 3, 2026, with a federal patch deadline of Aug 6, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an…

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that can allow an attacker to bypass normal login controls and take over accounts. It stems from an incomplete fix for an earlier related issue (CVE-2026-18556). For organizations that rely on N-central to manage endpoints and remote systems, successful abuse can give an attacker a foothold with the privileges of a compromised account, so timely assessment and remediation matter.

Public technical detail is limited to the class of flaw and the vendor/CISA guidance. Confirm exact affected builds, fixed releases, and deployment notes directly against the current N-able advisory before acting.

How it works

This issue is classified as CWE-288: authentication bypass using an alternate path or channel. In products of this type, authentication is supposed to be enforced consistently on every path that grants access to privileged functions. When an alternate path or channel does not apply the same checks—or when a prior patch left residual bypass routes—an attacker who can reach that path may obtain a session or account context without valid credentials.

In practical terms, the weakness can lead to authentication bypass and account takeover in N-central. Exact request patterns, endpoints, or preconditions are not provided in the available summary; defenders should treat any internet-exposed or broadly reachable N-central instance as higher risk until the vendor fix is confirmed applied. Do not assume exploit code or step-by-step mechanics beyond what the advisory states.

Am I affected? How to find it in your systems

N-able N-central is commonly deployed as a central management platform for MSPs and IT teams—often on dedicated servers or appliances, sometimes with cloud-connected components—and is used to administer agents, remote access, and automation across customer or internal estates.

When version or configuration detail is unclear, confirm against the vendor advisory rather than guessing.

How to remediate

Patch first. Apply the N-able update or mitigation package that addresses CVE-2026-18577, following the vendor’s installation and verification steps exactly. Because this vulnerability is described as the result of an incomplete patch for CVE-2026-18556, ensure you are on a build that fully closes both issues as stated by the vendor—not only a partial earlier update.

If you can't patch immediately

Until the vendor fix is installed, reduce attack surface and increase detection depth.

If your data may have been exposed

Actively exploited authentication-bypass flaws in management platforms can lead to account takeover and follow-on access to managed systems or stored operational data. Ransomware use specifically tied to this CVE is not documented in the provided facts. If you suspect compromise, isolate affected hosts, preserve logs and disk images per your incident process and CISA forensics triage guidance, rotate credentials, and hunt for persistence on N-central and downstream agents. As a routine check, you can run a free exposure scan of your email addresses against known breach datasets to see whether associated credentials have appeared in prior public breaches and prioritize resets accordingly.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedN-able · N-central
WeaknessCWE-288
Added to CISA KEVAug 3, 2026
Federal patch deadlineAug 6, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities