VORANT. Threat Intelligence Sign in Get the full feed

CISA flags N-able N-central auth bypass

high vulnerability government-national

CISA added an actively exploited authentication bypass vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog.

CISA has updated its Known Exploited Vulnerabilities (KEV) Catalog with CVE-2026-18577, an authentication bypass flaw in N-able N-central that uses an alternate path or channel to circumvent access controls. The vulnerability is confirmed to be under active exploitation, which triggers mandatory remediation timelines for Federal Civilian Executive Branch (FCEB) agencies under Binding Operational Directive (BOD) 26-04.

BOD 26-04 requires FCEB agencies to prioritize patching of KEV-listed vulnerabilities on internet-facing assets that could grant an attacker full control post-exploitation, and mandates compromise assessments in certain cases prior to patching. While the directive is binding only on federal agencies, CISA recommends that all organizations using N-able N-central treat this as a high-priority patching action given confirmed in-the-wild exploitation. N-able N-central is a remote monitoring and management (RMM) platform widely used by managed service providers, making authentication bypass vulnerabilities in this class of product particularly attractive to threat actors seeking broad downstream access to customer environments.

Mentioned in this report

Vulnerabilities CVE-2026-18577KEV

Source reporting: https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free