CVE-2026-18577
⚡ CISA KEVPublished: 2026-08-02Modified: 2026-08-04Vendor: N-ableProduct: N-central
8.1
CVSS v3
4.1%
EPSS
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
⚡ Added to KEV on 2026-08-03 · Federal agencies must remediate by 2026-08-06
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
CWE:CWE-288
💣 Public Exploits0
From Exploit-DB
No public exploits in Exploit-DB.
🔍 Sigma Detection Rules0
Rules tagged with this CVE
No Sigma rules tagged with this CVE.
🛠️ Patch Details1
Affected/fixed versions from threat intel reports
| N-able N-central | up to and including 2026.3.1 (prior to Hotfix 1) | 2026.3.1 Hotfix 1 (version 2026.3.1.7) | source ↗ |
📰 Threat Intel Coverage1
Digest reports mentioning this CVE
📎 References5
↗ https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm↗ https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/↗ https://www.cve.org/CVERecord?id=CVE-2026-18556↗ https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577↗ https://www.n-able.com/blog/n-central-security-update-august-2-2026