critical Known exploitedREV. 01
CVE-2026-18577N-able N-central — authentication bypass account takeover
The fix for CVE-2026-18556 in N-able N-central was incomplete. An unauthenticated attacker can still bypass login over the network through an alternate path and take over accounts in the remote monitoring platform, versions through 2026.3.1.
Read the risk
THE VITAL STATS- CVSS score
- 8.1/ 10 CVSS v3.1
- EPSS probability
- 54% Likelihood of exploitation
- Attack complexity
- High Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2026-08-02
- Added to KEV
- 2026-08-03
- Exploit published
- Not recorded
- Confidence
- medium
- Kill chain
- initial access
- MITRE ATT&CK
- T1190
- Severity
- critical
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attacker needsNetwork access to the N-central server's login interface; no account or user interaction needed, but the attack is technically demanding.
Fixed inN-central 2026.3 HF1
Behind the card
4 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Vendor advisorydocumentation.n-able.comdocumentation.n-able.com
- 04Vendor advisoryn-able.comn-able.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-09-22 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-09-22 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-09-22 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-09-22 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.