CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
highDetails
A high-severity vulnerability in N-able N-central, CVE-2026-18577, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. This flaw is an incomplete patch for a previous vulnerability, CVE-2026-18556, which is also listed on the KEV. The vulnerabilities allow for unauthorized actions on affected systems, leading to customer compromises.
Affected Systems
N-able N-central
Potential Impact
Compromise of the N-central remote monitoring and management platform, potentially leading to widespread unauthorized access to managed downstream customer endpoints, data exfiltration, and ransomware deployment.
Mitigations
Immediately apply patches provided by N-able. Per the CISA KEV directive, federal agencies must patch these vulnerabilities by the specified deadlines. All other organizations are strongly advised to patch immediately.