CVE-2026-18577
Incomplete patch leads to administrative account takeover
CVSS Score
0.0
EPSS Score
1.5%
EPSS Percentile
71th
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
| CWE | CWE-288 |
| Vendor | n-able |
| Product | n-central |
| Published | Aug 2, 2026 |
| Last Updated | Aug 4, 2026 |
โ ๏ธ Actively Exploited โ Act Now
Get instant alerts for n-able n-central
This vulnerability is actively exploited in the wild. Set up free real-time alerts so you're first to know about threats like CVE-2026-18577.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
N-able / N-central
0 โค 2026.3
References
documentation.n-able.com: https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm status.n-able.com: https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ cve.org: https://www.cve.org/CVERecord?id=CVE-2026-18556 cisa.gov: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577 n-able.com: https://www.n-able.com/blog/n-central-security-update-august-2-2026