Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

[KEV] CVE-2026-18577 -- CVSS 0.0 Vulnerability Briefing

[KEV] CVE-2026-18577 | CVSS 0.0 (Low) | Exploit: Operational

What Is It

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that can allow an unauthenticated attacker to take over accounts through an alternate authentication path or channel.

Technical Detail

The vulnerability results from an incomplete patch for CVE-2026-18556. An attacker may be able to use an alternate path or channel to bypass intended authentication controls and access N-central accounts without valid credentials. Successful exploitation can result in account takeover, potentially including access to accounts with elevated administrative privileges.

Exploitation Status

CISA has confirmed active exploitation in the wild. Exploit maturity is operational, meaning a usable exploitation capability is available and can be employed against vulnerable N-central deployments.

Who Is Targeting This

No specific threat actor attribution at this time. No confirmed or research-reported actors, targeted sectors, or associated campaigns have been identified in the available data.

What To Do

Prioritize installation of N-able's remediation for CVE-2026-18577 and verify that the update fully addresses both this issue and the incomplete remediation for CVE-2026-18556. CISA added this vulnerability to the Known Exploited Vulnerabilities Catalog on August 3, 2026; organizations should patch by the CISA-established remediation due date or apply mitigations where patching cannot be completed. Restrict access to N-central management interfaces to trusted administrative networks, review authentication and account activity for unexpected logins or privilege changes, rotate credentials for potentially affected accounts, and investigate any signs of unauthorized administrative access.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →