Home / Aug 05, 2026 / Story
0
#6 The Hacker News general August 04, 2026 at 07:00 UTC

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

By [email protected] (The Hacker News)

AI Summary

CISA added CVE-2026-18577 (CVSS 8.2) affecting N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed; the flaw is an incomplete patch for CVE-2026-18556 (also CVSS 8.2) that allows authentication bypass to gain administrator access. N-able N-central is widely used as an RMM platform by MSPs, making this a high-value target for threat actors seeking broad downstream access. Both hosted and on-premises N-central deployments are affected, and patching is urgent.

Relevance score: 85.0/100

# More from August 05