CiberLATAMbywhalemate

CVE-2026-18577 hits N-able N-central

N-able issued a hotfix for CVE-2026-18577, an active authentication bypass in N-central affecting MSPs.

Whalemate Labs · AI-assisted researchAug 4, 20263 min read

N-able released an emergency hotfix for N-central after identifying a security issue tracked as CVE-2026-18577, tied to an incomplete patch for a prior flaw and confirmed as actively exploited by several security firms.

Urgent hotfix for N-central

N-able said on its status page that it had been notified of a security issue affecting all N-central instances not running version 2026.3.1, tracked as CVE-2026-18577. The company also released a dedicated hotfix, build 2026.3.1.7, to mitigate the vulnerability.

The company said N-central 2026.3.1.7 includes the hotfix for CVE-2026-18577 and urged all customers to update immediately. CRN reported that message and said partners and customers were told to prioritize patching to address a flaw that allows remote administrative takeover of the RMM platform.

What the flaw allows

The NVD entry for CVE-2026-18577 describes the issue as an incomplete patch for CVE-2026-18556 that opens the door to authentication bypass and account takeover in N-central on versions up to 2026.3.1. The same technical description appears in BaseFortify and Rapid7, which classifies it as Authentication Bypass Using an Alternate Path or Channel, CWE-288.

Huntress expands on the impact and says the flaw lets remote attackers gain administrative access to N-central servers and abuse the Take Control feature to pivot into managed endpoints. Security Arsenal, meanwhile, says unauthenticated attackers can bypass the N-central login portal and obtain remote administrative access, affecting all builds earlier than 2026.3.1.7.

Active exploitation and scope

Arctic Wolf said threat actors are actively exploiting CVE-2026-18556 and CVE-2026-18577, and noted that N-able began investigating anomalous activity on July 31, 2026. According to that report, the emergency hotfix 2026.3.1.7 was released on August 2, 2026, to address both vulnerabilities.

The Hacker News reported that attackers used CVE-2026-18577 to gain remote administrative access to N-central servers and reach customer systems managed through those servers. The publication also said the flaw affects builds earlier than 2026.3.1.7 and that N-able shipped that build on August 2, 2026, as the first unaffected version.

NCSC-FI reinforced that view, saying all versions released before the emergency hotfix of August 2, 2026, are vulnerable and clarifying that the first non-vulnerable build is 2026.3.1.7.

Indicators of compromise and risk assessment

In its official advisory, N-able listed specific indicators of compromise for MSPs to check environments potentially affected by CVE-2026-18577 exploitation: a file named svchost.exe in the Documents folder of managed users, a registered service called Cloudflared, and inbound connections from IPs 173.249.252.200 and 87.249.138.34.

WindowsForum cited the CISA catalog as a repository where this actively exploited authentication bypass in N-able N-central was added. At the same time, severity scores vary by vendor: Tenable assigned CVSS v3.1 9.8 Critical, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, while N-able rated it CVSS 4.0 at 8.2 High, and Rapid7 also placed it at 8.2 High under CWE-288. SecNews also reported that N-able recommended immediately installing the N-central 2026.3 Hotfix 1, and that all installations not running 2026.3.1 remain affected.

ThreatLocker had previously warned that the vulnerability allowed unauthenticated users to reach god mode privileges and recommended updating to version 2026.3.1.7. A technical video on YouTube also said N-able confirmed active exploitation and that all builds earlier than 2026.3.1.7 fall within the affected range.

The official mitigation also set out direct upgrade paths to the safe 2026.3.1.7 version, with the option to upgrade to 2026.3.1 from builds 2025.4 and 2026.1.

Sources

View all