CISA Updates KEV Catalog with Exploited N-able N-Central Vulnerability CVE-2026-18577 Following Customer Breaches
CISA added the high-severity N-able N-central vulnerability CVE-2026-18577 to its KEV catalog after confirming active exploitation in the wild, enabling authentication bypass and administrative access. The flaw affects unpatched versions, with indicators of compromise including malicious files and VPN-exit node IP addresses linked to threat actors.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows
*** END OF TRANSMISSION ***