An authentication bypass vulnerability (CVE-2026-18577) has been discovered in N-able's remote monitoring and management (RMM) solution, 'N-able N-central'. This vulnerability has been confirmed to be actively exploited in widespread attacks, leading the U.S. CISA (Cybersecurity and Infrastructure Security Agency) to add it to their Known Exploited Vulnerabilities (KEV) catalog and urge immediate action. Because administrator privileges for N-able N-central could be seized and managed endpoints compromised, all affected users must update to the patched version immediately.
Immediate Actions to Take
- ✓Urgently update N-able N-central to version 2026.3.1.7 hotfix.
- ✓Consider isolating your N-central environment until the update is complete, and thoroughly check for any signs of potential compromise.
- ✓Enforce multi-factor authentication (MFA) and regularly audit user account access permissions.
- ✓Monitor and review N-central servers and managed endpoints for suspicious logins, account changes, job or automation modifications, and Take Control session history.
Vulnerability Overview and Scope of Impact
CVE-2026-18577 is an authentication bypass vulnerability that arose due to an incomplete patch for a previously fixed vulnerability (CVE-2026-18556). Exploiting this flaw allows a remote attacker to bypass N-able N-central's authentication mechanism and gain administrator privileges. All N-central versions prior to 2026.3.1.7 are affected. A successful attack could grant the attacker 'God-mode' control over the N-central console, allowing them to push scripts, deploy tools, or initiate remote control sessions on managed servers and workstations, including critical systems like domain controllers.
Specific Impact and Attack Scenarios
In attacks exploiting this vulnerability, attackers remotely gain administrator access to N-central servers. They then use the 'Take Control' feature to connect to systems within customer environments managed by N-central. Confirmed attacks have involved registering new CloudFlare tunnel services on compromised devices, enabling persistent access to the environment even after N-central server access was revoked. CISA notes that this type of vulnerability is a frequent attack vector for malicious cyber actors and poses a significant risk to federal government agencies.
Impact by Major Distribution
While N-able N-central servers run on a custom distribution of AlmaLinux 9, this vulnerability stems from a flaw in the N-central application layer's authentication mechanism, not the OS kernel or OSS middleware itself. However, Huntress warns that EDR (Endpoint Detection and Response) software is often not deployed in AlmaLinux-based RMM appliance environments, which could delay attack detection after a system has been compromised via RMM.
Response Procedures and Verification Methods
N-able has released the N-central 2026.3.1.7 hotfix and strongly recommends that all customers upgrade to this version immediately. Even after updating, it is crucial to continue following security best practices such as regular patching, implementing multi-factor authentication, auditing user access, and monitoring for unusual activity. Enhance log analysis and network traffic monitoring to check for signs of compromise.
📦Reference Sources and Official Patch Information
- N-able Security Update – August 2, 2026↗
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-18577)↗
- CISA KEV Catalog: CVE-2026-18577↗
- Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation - Huntress↗
- CVE-2026-18577 - CVE Record↗
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete - ChannelE2E↗
