CVE-2026-18577 is a high-severity authentication bypass vulnerability affecting N-able N-central, a remote monitoring and management platform used by MSPs and IT teams.
The vulnerability exists because a previous patch for CVE-2026-18556 addressed one exploitation path but left an alternate path to the same underlying weakness accessible. Successful exploitation can allow an attacker to bypass authentication and take over administrative accounts, potentially providing control over the endpoints managed by the affected N-central server.
N-able has confirmed active exploitation of CVE-2026-18577 in the wild. Self-hosted customers should immediately upgrade to build 2026.3.1.7, as upgrading only to 2026.3.1 is not sufficient.
RedLegg will occasionally communicate vulnerabilities released outside the usual release schedule to provide additional value to our customers. These emergency bulletins describe vulnerabilities or threats we classify as the highest severity level and warrant out-of-band emergency patching or mitigation action.
N-able N-central Incomplete Patch Leads to Administrative Account Takeover
Identifier: CVE-2026-18577
PoC or Exploitation:
N-able confirmed CVE-2026-18577 was actively exploited in the wild.
CVSS Score: 8.2 (High, CVSS v4.0)
Update / Patch:
N-able has released build 2026.3.1.7, the first version confirmed unaffected. Upgrading only to 2026.3.1 is not sufficient.
Hosted N-central (NCOD) instances are being upgraded automatically by N-able on a rolling schedule; no customer action required.
Self-hosted N-central customers must upgrade manually to build 2026.3.1.7.
N-able advisory and upgrade guidance:
Description:
CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central, a remote monitoring and management platform used by MSPs and IT teams to administer customer endpoints. The flaw exists because a prior patch for CVE-2026-18556 closed one exploitation path but left an alternate path to the same underlying weakness open.
An attacker exploiting this alternate path can bypass authentication entirely and take over administrative accounts on the N-central server, gaining the same level of control a legitimate administrator would have over every managed endpoint the server oversees.
Mitigation Recommendation:
Upgrade all self-hosted N-central instances to build 2026.3.1.7 immediately.
Restrict N-central console access to trusted administrative networks or VPNs.
Enforce multi-factor authentication on all N-central administrative accounts.
To determine whether a server may have been impacted, check managed endpoints for a file named svchost.exe located in a user's Documents folder; this is not the legitimate Windows binary and is anomalous in that location and for a registered service named Cloudflared.
If exploitation is suspected, contact N-able support immediately and engage your own security team.