HomeSecurityN-central: Critical vulnerability in CISA's KEV after breaches

N-central: Critical vulnerability in CISA's KEV after breaches

CISA has added a serious vulnerability affecting N-able N-central , the widely used Remote Monitoring and Management (RMM) platform for managed service providers, to its list of Known Exploited Vulnerabilities (KEV). The vulnerability , CVE-2026-18577 , with a CVSS score of 8.2 , allows authentication bypass and full administrative account takeover in vulnerable versions of the software, putting hundreds of organizations worldwide at risk.

See also: CVE-2026-63030: critical WordPress vulnerability in CISA KEV as actively exploited

N-central vulnerability CVE-2026-18577 CISA KEV authentication bypass

The vulnerability is essentially an incomplete patch for a previous vulnerability, CVE-2026-18556 (also CVSS 8.2, CWE-288), which was previously patched. Attackers discovered that an alternative authentication path remained accessible, allowing them to bypass login mechanisms without valid credentials. N-able released emergency version 2026.3.1.7 on August 2, 2026 as the first unaffected version, while CISA added the vulnerability to KEV on August 3, 2026.

Successful exploitation of the vulnerability allows remote attackers to gain administrative access to vulnerable N-central and then abuse the built-in Take Control to move laterally to managed endpoints and install persistence mechanisms. Huntress said it has observed threat actors targeting the vulnerability across multiple organizations, although there is no indication that the campaign has escalated into a broad, indiscriminate attack.

N-central CVE-2026-18577: Technical details and attack vectors

N -central is a platform designed to manage hundreds or thousands of endpoint devices from a central server, making it an extremely attractive target for cybercriminals. A breach of a single N-central can expose entire customer environments, including domain credentials, API , and private SSH stored on the platform.

CVE -2026-18577 affects all N-central versions up to 2026.3.1 . The attack vector is an alternative authentication path ( CWE-288 ) that allows an attacker to reach privileged operations without valid credentials. Once they gain access, attackers use N-central 's Take Control feature to connect to managed endpoints, and in some cases have used Cloudflare tunnels to establish a persistent presence on victim networks.

Among the indicators of compromise ( IoC ) shared by N-able , a malicious login via the username “MSP Support” — a default username associated with legitimate Take Control sessions — from the IP address 173.249.252[.]200 stands out . All of the detected IP addresses are Mullvad or NordVPN VPN exit nodes , suggesting that the attackers are taking steps to hide their identity.

Patterns observed after successful exploitation include: high-level reconnaissance to locate critical servers such as domain controllers, enumeration of running processes on compromised hosts before disconnecting, and lateral movement to other hosts within the affected organizations' environments after gaining initial access.

See also: N-central CVE-2026-18577: New N-able hotfix for administrators

CVE-2026-18577 - SecNews.gr

N-central and the history of vulnerabilities: A recurring problem

This is not the first time that N-central has been the focus of serious vulnerabilities. Almost exactly a year ago, two other vulnerabilities in the same product — CVE-2025-8875 (unsafe deserialization) and CVE-2025-8876 ( command injection) — were exploited in targeted attacks against on-premises environments. Both of these vulnerabilities were also added to the CISA KEV list .

Additionally, CVE-2025-11700 , an XXE information disclosure vulnerability affecting versions prior to 2025.4 , was also disclosed in 2025, highlighting a troubling pattern of recurring high-risk vulnerabilities in the same product. Horizon3.ai had previously reported that the combination of vulnerabilities in N-central allowed attackers to gain access to legacy APIs , read sensitive files, and obtain credentials that led to a breach of the N-central database and its stored secrets.

The fact that CISA has added multiple N-central to KEV in less than a year highlights the strategic value that cybercriminals place on RMM. Compromising a central management server gives access to dozens or hundreds of client organizations simultaneously, making these platforms particularly attractive targets for groups seeking mass access with minimal effort.

Protecting against the N-central CVE-2026-18577 vulnerability: What to do now

Organizations using N-able N-central should immediately upgrade to version 2026.3.1.7, which is the first unaffected version. The upgrade applies to both cloud-hosted and on-premises installations. Any N-central running a version prior to 2026.3.1.7 during the active exploitation window should be treated as potentially compromised.

Security teams should also review administrative accounts, API, service accounts, and integrations for unauthorized changes. It is critical to look for signs of persistence or lateral movement emanating from the management server, such as unexpected remote access tools, tunnels, new services, or unusual endpoint management actions. Revoking and rotating credentials that may be stored or accessible through N-central — including domain credentials, API keys , and SSH keys — is a necessary precaution.

See also: Rails Active Storage: critical vulnerability CVE-2026-66066 (CVSS 9.5) exposes secrets

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

CISA warning ColdFusion Langflow Joomla KEV vulnerabilities

For long-term protection, organizations should limit exposure of RMM consoles to the internet, enforce multi-factor authentication (MFA) , and restrict administrative access to trusted management networks. Federal FCEBs have been instructed to apply the fixes by August 6, 2026 , and monitor Take Control activity in their environments. Rapid response is imperative: the inclusion of a vulnerability in CISA ’s KEV signals confirmed active exploitation , not just a theoretical risk.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS