CVE-2026-18577
Act now ● On CISA KEV — actively exploited
Actively exploited — on the CISA KEV list.
CVSS base
8.1
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS — probability of exploitation (30 days)
54.1%
99.0th percentile
CISA KEV
Listed
Added 2026-08-03 · patch by 2026-08-06
Weakness / dates
CWE-288
Published 2026-08-02 · modified 2026-08-04
CVSS breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
| Attack Vector | N | Network |
| Attack Complexity | H | High |
| Privileges Required | N | None |
| User Interaction | N | None |
| Scope | U | Unchanged |
| Confidentiality | H | High |
| Integrity | H | High |
| Availability | H | High |
Timeline
- 2026-08-02 — Published (NVD)
- 2026-08-03 — Added to CISA KEV (actively exploited)
- 2026-08-06 — CISA patch-by deadline
- 2026-08-04 — Last modified (NVD)
Description
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Affected
References
- https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm
- https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
- https://www.cve.org/CVERecord?id=CVE-2026-18556
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577
- https://www.n-able.com/blog/n-central-security-update-august-2-2026