CiberLATAMbywhalemate

CVE-2026-18577 hits N-able N-central

N-able issued a hotfix for CVE-2026-18577, an active authentication bypass in N-central affecting MSPs.

Whalemate Labs · AI-assisted researchPublished:Updated 3 min read

N-able released an emergency hotfix for N-central after identifying a security issue tracked as CVE-2026-18577, tied to an incomplete patch for a prior flaw and confirmed as actively exploited by several security firms.

N-able said CVE-2026-18577 affects every N-central instance that is not running version 2026.3.1. The company released a hotfix identified as build 2026.3.1.7 and urged all customers to update immediately. The flaw has already been actively exploited, enables authentication bypass, and exposes MSPs and managed environments.

What did N-able say about the hotfix?

N-able said on its status page that it had been notified of a security issue affecting all N-central instances not running version 2026.3.1, and that the case is tracked as CVE-2026-18577. The company also released a specific hotfix, identified as build 2026.3.1.7, to mitigate the vulnerability.

The company said the N-central 2026.3.1.7 update includes the hotfix for CVE-2026-18577 and recommended that all customers update immediately. CRN reported that message and said partners and customers were urged to prioritize patching to address a flaw that allows remote administrative takeover of the RMM platform.

What does the flaw in N-central allow?

The NVD entry for CVE-2026-18577 describes the issue as an incomplete patch for CVE-2026-18556 that opens the door to authentication bypass and account takeover in N-central versions up to 2026.3.1. The same technical description appears in BaseFortify and in Rapid7, which classifies it as an Authentication Bypass Using an Alternate Path or Channel, CWE-288.

Huntress expands on the impact and says the flaw allows remote attackers to gain administrative access to N-central servers and abuse the Take Control feature to pivot into managed endpoints. Security Arsenal, for its part, says unauthenticated attackers can bypass the N-central login portal and obtain remote administrative access, affecting all builds earlier than 2026.3.1.7.

Is active exploitation confirmed, and since when?

Arctic Wolf said threat actors are actively exploiting CVE-2026-18556 and CVE-2026-18577, and noted that N-able began investigating anomalous activity on July 31, 2026. According to that report, the emergency hotfix 2026.3.1.7 was released on August 2, 2026, to remediate both vulnerabilities.

The Hacker News reported that attackers exploited CVE-2026-18577 to gain remote administrative access to N-central servers and reach managed customer systems through those servers. The outlet also said the flaw affects builds earlier than 2026.3.1.7, and that N-able distributed that build on August 2, 2026, as the first unaffected version.

NCSC-FI reinforced that reading by saying all versions available before the emergency hotfix of August 2, 2026 are vulnerable, and clarified that the first non-vulnerable build is 2026.3.1.7.

What indicators of compromise did N-able publish?

In its official advisory, N-able listed specific indicators of compromise for MSPs to check in environments potentially affected by CVE-2026-18577 exploitation: a file called svchost.exe in the Documents folder of managed users, a registered service named Cloudflared, and inbound connections from IPs 173.249.252.200 and 87.249.138.34.

WindowsForum cited CISA's catalog as the repository where this actively exploited authentication bypass vulnerability in N-able N-central was added. At the same time, severity scores vary by vendor: Tenable assigned CVSS v3.1 9.8 Critical, with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, while N-able rated it CVSS 4.0 at 8.2 High, and Rapid7 also placed it at 8.2 High under CWE-288. SecNews also reported that N-able recommended installing the N-central 2026.3 Hotfix 1 immediately, and that all installations not running 2026.3.1 remain affected.

ThreatLocker had previously warned that the vulnerability allowed unauthenticated users to reach god mode privileges and recommended updating to version 2026.3.1.7. A technical video on YouTube also said N-able confirmed active exploitation and that all builds earlier than 2026.3.1.7 fall within the affected range.

The official mitigation also outlined direct upgrade paths to the safe 2026.3.1.7 version, with an option to upgrade to 2026.3.1 from builds 2025.4 and 2026.1.

Sources

View all