• Request consultation
  • Newsletter
  • Deutsch Deutsch German de
  • English English English en
  • Italiano Italiano Italian it
  • Nederlands Nederlands Dutch nl
Greenbone
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for Your Sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap & Lifecycle
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
  • Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • Click to open the search input field Click to open the search input field Search
  • Menu Menu
  • Products
    • OPENVAS BASIC
      • OPENVAS BASIC: Order
    • OPENVAS SCAN
    • Upcoming Solutions
      • OPENVAS SECURITY INTELLIGENCE
      • OPENVAS AI
    • Solutions for your sector
      • Educational Sector
      • Healthcare Sector
      • Public Sector
    • Technology
      • Feed Comparison
      • Product Comparison
        • OPENVAS vs. Nessus
      • Roadmap and Lifecycle
    • Request IT Security
  • Service & Support
    • Professional Services
    • Documents
    • Technical Support
  • Events
    • Cybersec Europe 2026
    • Webinars
  • Partners
    • MSSP
  • About Greenbone
    • Our History
    • Careers
    • Contact
    • Newsletter
  • Our Blog
    • Know-how
      • Attack Vector Timeline
      • Cyberattacks and Defense
      • Cyber Defense Security
      • Cyber Resilience Act
      • Data Security
      • Digital Operational Resilience Act
      • Exposure Management
      • IT and Information Security
      • NIS2 Directive
      • Open Source Vulnerability Management
      • The Vulnerability Timeline
  • German
  • English
  • Italian
  • Dutch
Joseph Lee

Patch Now! CVE-2026-18577 in N-able N-central Actively Exploited

Blog

CVE-2026-18577 (CVSS 8.2, EPSS ≥ 71st pctl) and CVE-2026-18556 (CVSS 7.4, EPSS ≥ 19th pctl), published in early August, have both been added to CISA’s Known Exploited Vulnerabilities (KEV) list within days of their disclosure [1][2]. N-able has published Indicators of Compromise (IoC) and post-exploitation activity from successful attacks against its own hosted N-central instances. N-central version 2026.3.1 is required to remediate both CVEs.

CVE-2026-18577 is considered a bypass of the fix for CVE-2026-18556. Both are authentication bypass [CWE-288] flaws that allow admin-level account takeover and full-platform compromise of N-central servers. No public proof-of-concept (PoC) exploit code or detailed technical analysis has been published for CVE-2026-18556 or CVE-2026-18577. Several national CERT agencies have published alerts for the CVEs [1][2][3][4][5][6][7].

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check that identifies instances of N-able N-central vulnerable to CVE-2026-18577 and by hierarchy, CVE-2026-18556. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

Shattered shield graphic warning that an N-central vulnerability on the N-able platform is being actively exploited

A Risk Assessment of CVE-2026-18577 and CVE-2026-18556 Affecting N-able N-central

On July 31st, 2026, N-able detected malicious activity targeting N-central server in a customer environment. Analysis led to the discovery of a zero-day vulnerability, which was initially assigned CVE-2026-18556. The flaw was remediated in N-central 2026.2, but the fix left an alternate authentication-bypass path. N-able assigned CVE-2026-18577 to track the incomplete fix separately. N-central 2026.3 Hotfix 1 was released on August 2nd, which fully remediates both CVEs.

CVE-2026-18577 and CVE-2026-18556 are high risk because of N-central’s role as a remote administration platform in Managed Service Provider (MSP) environments. N-central includes tooling such as Take Control, Remote Desktop, Extensible Messaging and Presence Protocol (XMPP) control channels, and SSH access, among other services.

As evidenced by N-able’s reports of post-exploitation activity, compromise of an N-central server creates broad downstream risk across managed customer environments. Defenders should treat the issue as a platform-wide operational risk rather than limited to a single component or attack surface.

Multiple sources report that roughly 3,000 N-central servers were exposed to the public internet in 2025 [1][2]. Shodan currently identifies approximately 2,300 instances. This recent incident is not the first time that N-central has come under active exploitation. In mid-2025, CVE-2025-8875 (CVSS 7.8) and CVE-2025-8876 (CVSS 8.8) were both added to CISA’s KEV list [3][4].

Technical Assessment and Attack Trajectory

CVE-2026-18577 (CVSS 8.2, EPSS ≥ 71st pctl) is the result of an incomplete patch for CVE-2026-18556 (CVSS 7.4, EPSS ≥ 19th pctl), which was published only one day before CVE-2026-18577. Both flaws are described as authentication bypass vulnerabilities [CWE-288] affecting N-central instances. Post-exploitation reporting indicates that they allow admin-level account takeover and full-platform compromise. The vendor-supplied evidence does not include root-cause details or identify specific exploitable components. No further technical analysis or PoC exploits have been published.

N-able has published indicators of compromise (IoC) and post-compromise details from successful attacks on its hosted N-central infrastructure. These include a rogue file named svchost.exe in the user’s Documents folder, a registered service named Cloudflared, and inbound connections from several IP addresses. For defenders, this means that the patches should be paired with a full forensic review of exposed systems and monitoring of network traffic for anomalous activity.

Observed post-compromise activity included:

  • Gaining administrative access to vulnerable N-central servers [T1190]
  • Using N-central’s Take Control function to access connected systems remotely [T1219.002]
  • Installing a rogue service [T1543.003] named Cloudflared on managed endpoints for persistent remote access even after access through the N-central server was revoked

CVE-2026-18577 & CVE-2026-18556: Affected Versions and Mitigation

CVE-2026-18577

CVSS 8.2 · HighEPSS 1.5% (71st)Actively exploitedIn CISA KEV

CVE-2026-18556

CVSS 7.4 · HighEPSS 0.3% (19th)Actively exploitedIn CISA KEV

Defenders should be primarily concerned about CVE-2026-18577 since it is a bypass of an earlier flaw. CVE-2026-18577 affects all N-central instances prior to version 2026.3.1. N-able’s status page states that hosted N-central instances are upgraded automatically. However, self-hosted customers must apply the 2026.3 Hotfix 1, identified as build 2026.3.1.7.

Deployment Affected versions Fixed versions Upgrade path

Hosted N-central

All versions before 2026.3.1

N-central 2026.3 HF1, build 2026.3.1.7

Automatic update by N-able

Self-hosted N-central

All versions before 2026.3.1

N-central 2026.3 HF1, build 2026.3.1.7

Manual update required

N-able has published IoCs for its own incident response forensic analysis. The IoC information suggests that responders review potentially impacted systems for a file named svchost.exe in the user’s Documents folder, a registered service named Cloudflared, and inbound connections from several observed IP addresses.

Summary

N-able has issued N-central 2026.3 HF1 to mitigate CVE-2026-18577, which affects all previous versions of N-central. Because N-central is an administrative platform used by MSPs to manage customer environments, the operational risk is high. Known IoCs are available from the analysis of real-world breaches. Defenders should pair hotfix deployment with a full forensic review of potentially compromised systems.

Start Your Free Trial

Greenbone’s OPENVAS ENTERPRISE FEED includes a remote banner version check that identifies instances of N-able N-central vulnerable to CVE-2026-18577 and by hierarchy, CVE-2026-18556. Grabbing a copy of OPENVAS SCAN with a free two-week trial of the OPENVAS ENTERPRISE FEED is a surefire way to gain the deepest insight into where software vulnerabilities exist in your organization’s Linux infrastructure.

 

Contact Test Now Buy Here Back to Overview
Joseph Lee
Joseph Lee

Joseph has had a varied and passionate background in IT and cyber security since the late 1980s. His early technical experience included working on an IBM PS/2, assembling PCs and programming in C++.

He also pursued academic studies in computer and systems engineering, anthropology and an MBA in technology forecasting.

Joseph has worked in data analytics, software development and, in particular, enterprise IT security. He specialises in vulnerability management, encryption and penetration testing.

LinkedIn

6. August 2026/by Joseph Lee
Share this entry
  • Share on LinkedIn
  • Share by Mail
https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png 0 0 Joseph Lee https://www.greenbone.net/wp-content/uploads/greenbone-logo-2025.png Joseph Lee2026-08-06 08:47:522026-08-06 08:51:48Patch Now! CVE-2026-18577 in N-able N-central Actively Exploited

Search

Search Search

Archive

  • 2026
  • 2025

Newsletter

Subscribe Now

OPENVAS BASIC

Our entry-level enterprise product

Test 14 Days Free of Charge

Products & Solutions

  • OPENVAS PRODUCTS
  • OPENVAS SECURITY INTELLIGENCE
  • OPENVAS SCAN
  • OPENVAS BASIC
  • OPENVAS FREE
  • OPENVAS AI
ISO9001-EN

Service & Support

  • Professional Services
  • Documents
  • Technical Support
  • FAQ
  • Warranty
  • Cyber Resilience Act
ISO27001-EN

About us

  • About Greenbone
  • Partners
  • MSSP
  • License information
  • Privacy Statement
  • Terms & Conditions
ISO14001-EN

Contact with us

  • Contact
  • Newsletter
  • Media Contact
  • Careers
  • Security Response
  • Imprint
  • Grounding Page

Community

  • Community Portal
  • Community Forum
© Copyright - Greenbone AG 2020-2026
  • Link to LinkedIn
Link to: CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered! Link to: CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered! CIS Benchmarks for Microsoft Environments: Greenbone’s Got You Covered!
Scroll to top Scroll to top Scroll to top
Contact
Request IT Security Contact Us Subscribe to Newsletter Follow on LinkedIn