#6
The Hacker News
general
August 04, 2026 at 07:00 UTC
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
By [email protected] (The Hacker News)
AI Summary
CISA added CVE-2026-18577 (CVSS 8.2) affecting N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed; the flaw is an incomplete patch for CVE-2026-18556 (also CVSS 8.2) that allows authentication bypass to gain administrator access. N-able N-central is widely used as an RMM platform by MSPs, making this a high-value target for threat actors seeking broad downstream access. Both hosted and on-premises N-central deployments are affected, and patching is urgent.
Relevance score: 85.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →