N-able has warned customers that attackers are actively exploiting an authentication bypass flaw, CVE-2026-18577, in N-central hosted and on-premises servers, with a hotfix now available for all affected versions before 2026.3. The issue stems from an incomplete patch for CVE-2026-18576 and could lead to administrative account takeover, prompting urgent updates and close monitoring. #Ncentral #CVE-2026-18577 #CVE-2026-18576 #N-able
Keypoints
- N-able says attackers are exploiting CVE-2026-18577 in N-central servers.
- The flaw affects both hosted and on-premises deployments before version 2026.3.
- Hotfix 2026.3.1.7 has been released and is strongly recommended.
- CVE-2026-18577 comes from an incomplete fix for CVE-2026-18576.
- Indicators of compromise include specific IPs, Cloudflared, and svchost.exe in a documents folder.