we_are_coded.by CODE · The world, decoded
БГ
CISA

A second patch for N-able N-central: the first one was incomplete, and the hole is already being exploited

CISASecurity

CISA added CVE-2026-18577 to the catalog of actively exploited vulnerabilities: authentication bypass and account takeover in N-central - the tool providers use to manage other people's networks. The vulnerability is the result of an incomplete earlier fix.

In short
  • CVE-2026-18577: authentication bypass by an alternate path and account takeover in N-able N-central.
  • In CISA's KEV catalog since 3 August - meaning the exploitation is proven, not theoretical.
  • The root cause, per CISA's description: an incomplete earlier patch; the full fix is N-central 2026.3 HF1.
Checked on4 August 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The second patch always says more than the first. The first says: we found a hole. The second says: and we didn't close it.

The facts: on 3 August CISA added CVE-2026-18577 to the KEV catalog - the list of vulnerabilities with proven active exploitation. Affected is N-able N-central, a remote management platform MSP providers use to administer their clients' networks. The hole is an authentication bypass by an alternate path, leading to account takeover, and per CISA's description is the result of an incomplete fix for an earlier vulnerability. N-able has released N-central 2026.3 HF1 and a status bulletin. Sources: CISA's KEV catalog; N-able's release notes, 03.08.2026.

N-central isn't just any system - it's a key to many houses at once. If someone gets into the provider's tool, they get into its clients too. That's why platforms like this are a favorite target: one hole, many doors. And an incomplete patch is a classic of the genre. Attackers read the differences between versions more carefully than most administrators do - they see what got patched and what got missed, and they hit what was missed.

If you're running N-central - HF1 right away. If you're paying a provider who runs it - ask them which patch number they've applied. The first one doesn't count anymore.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog (CVE-2026-18577, added 03.08.2026)→N-able - N-central 2026.3 HF1 Release Notes
Original: https://wearecoded.com/en/articles/cisa-kev-nable-ncentral-nepalen-fiks.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news