Security advisories

N-central Vulnerability (CVE-2026-18577) Under Exploitation

August 4, 2026

3 MINS READ

THE THREAT

On August 2nd, 2026, N-able disclosed CVE-2026-18577, an authentication bypass vulnerability impacting N-central instances. The vulnerability is due to an incomplete patch that was released to address CVE-2026-18556 (CVSS: 7.4), another authentication bypass flaw which was disclosed on August 1st. Exploitation of CVE-2026-18577 (CVSS: 8.1) could result in attackers bypassing authentication and account takeover in N-central, granting full administrative access to an N-central console. A hotfix was released under version 2026.3.1 to address the flaw.

N-able confirmed that exploitation has been identified in a "limited number of customers". As exploitation is ongoing, organizations utilizing N-central within their environment must ensure that relevant patches are applied.

What we're doing about it

What you should do about it

Additional information

N-central is a Remote Monitoring and Management (RMM) platform that is commonly used by Managed Service Providers (MSPs) to monitor, patch, and remotely access endpoints across their customer base. On August 1st, N-able disclosed CVE-2026-18556 following investigation into "an increase in licensing issues". This vulnerability was addressed in version 2026.2, which was later identified as incomplete, and leading to CVE-2026-18577. N-able notes that "a limited number of customers" were identified to have been impacted by the flaw, which allowed attackers to obtain remote administrative access, and registered services for a Cloudflare tunnel to enable persistence.

Following this disclosure, Huntress identified exploitation of CVE-2026-18577 "across multiple organizations" but did not have evidence at the time of publication to suggest that attacks were widespread. These attacks involved high-level reconnaissance to identify key targets, process enumeration, and lateral movement. Targeting widely used MSP tools underscores how threat actors can leverage trusted third-party management platforms to conduct large scale supply chain attacks, where the exploitation of this flaw could grant access to multiple downstream organizations.

CISA also added CVE-2026-18577 to its Known Exploited Vulnerabilities (KEV) catalog, giving Federal Civilian Executive Branch (FCEB) agencies a deadline of August 6th to ensure that relevant patches are applied. At the time of writing, Proof-of-Concept (PoC) exploit code has not been made publicly available for either CVE-2026-18556 or CVE-2026-18577; however, this can rapidly change. As exploitation is ongoing, organizations that utilize N-central within their environment should immediately apply the relevant hotfix.

IOCs Identified by N-able
37[.]153[.]90[.]88 Attacker IP Address
173[.]249[.]252[.]200 Attacker IP Address
92[.]118[.]112[.]181 Attacker IP Address
87[.]249[.]138[.]34 Attacker IP Address
37[.]19[.]210[.]32 Attacker IP Address
68[.]235[.]46[.]214 Attacker IP Address
IOCs Identified by Huntress
mousears[.]synology[.]me Known Malicious Domain
wagoosh[.]direct[.]quickconnect[.]to Known Malicious Domain
who-ripped-one[.]direct[.]quickconnect[.]to Known Malicious Domain

References:
[1] https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
[2] https://www.n-able.com/blog/n-central-security-update-august-2-2026
[3] https://nvd.nist.gov/vuln/detail/CVE-2026-18556
[4] https://nvd.nist.gov/vuln/detail/CVE-2026-18577
[5] https://www.huntress.com/blog/n-able-vulnerability-exploitation
[6] https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog

Back to Security Advisories

Speak With A Security Expert Now

TALK TO AN EXPERT
View Most Recent Advisories