Skip to content

N-able N-central: Actively Exploited Vulnerability CVE-2026-18577 Requires Immediate Patching

Bottom line: On August 1, 2026, N-able released a hotfix for the actively exploited vulnerability CVE-2026-18577 in N-central, after a previous patch for CVE-2026-18576 failed to fully close the gap.

A patch initially released for the vulnerability CVE-2026-18576 in N-able N-central did not fully close the gap. On August 1, 2026, N-able provided a hotfix against the subsequent vulnerability CVE-2026-18577, which, according to the vendor, is already being actively exploited.

N-central is a platform from N-able for Remote Monitoring and Management (RMM) of endpoints, primarily used by Managed Service Providers (MSPs) for the centralized management of customer infrastructures. A patch originally released addressed the vulnerability CVE-2026-18576, but did not fully close it. As a consequence, N-able released a hotfix on August 1, 2026, against a further, related vulnerability identified as CVE-2026-18577. According to the source, this vulnerability is already being actively exploited.

For security leaders, this case is relevant for several reasons: RMM solutions such as N-central typically hold far-reaching administrative rights over managed endpoints and networks, as they are designed precisely for this purpose. A successful compromise of such a platform can potentially give attackers access to numerous downstream customer systems, provided the solution is deployed at an MSP. In addition, the incomplete initial patch shows that initial fixes should not automatically be considered sufficient, and that follow-up advisories need to be tracked.

CISOs and IT leaders who use N-able N-central in-house or via a service provider should immediately check whether the hotfix from August 1, 2026 has already been applied. Since active exploitation is already being reported, it is also advisable to review existing logs for signs of compromise during the period between the original release of CVE-2026-18576 and the availability of the hotfix for CVE-2026-18577. Organizations that use N-central through an MSP should actively ask the service provider whether and when the patch was applied.


Source: borncity.com · Published August 4, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: