Skip to content
September 14, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Vulnerability Report
  • CVE-2026-18577: N-central Account Takeover Exploited in the Wild
  • Vulnerability Report

CVE-2026-18577: N-central Account Takeover Exploited in the Wild

Do Son August 3, 2026 2 minutes read
0
N-central account takeover vulnerability CVE-2026-18577 exploited via authentication bypass
Add Daily CyberSecurity as a preferred source on Google

TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete patch for an earlier bug left the door open. A hotfix for version 2026.3.1.7 closes the gap.

At a glance
  • CVE: CVE-2026-18577
  • CVSS: 8.2 (High · CVSSv4)
  • Product: N-able N-central
  • Affected: ≤ 2026.3
  • Impact: Incomplete patch leads to administrative account takeover
  • Status: Exploited in the wild
  • Patched in: 2026.3.1.7
  • EPSS: 54.1% (30-day)
  • Action: Update to 2026.3.1.7 now

Track every CVE that hits your stack the moment it's exploited.

Get free email alerts →

Why it matters

N-central is a remote monitoring and management platform used by managed service providers. A N-central account takeover on this platform can cascade into every customer environment it oversees. N-able’s own account of the incident states plainly that “an attacker had identified a vulnerability on all N-central servers running a version prior to 2026.3.1.7, which allowed them to obtain administrative access remotely.”

How the attack works

CVE-2026-18577 is a bypass of the fix N-able shipped earlier for a related flaw, CVE-2026-18556. After gaining administrative access, attackers used the platform’s own Take Control feature to reach managed endpoints. On those devices, they registered a Cloudflare tunnel as a persistent service, allowing continued access even after the N-central server itself was secured.

Running the tunnel as a service means it survives a reboot and needs no open inbound port, since it connects outward to Cloudflare’s network. This N-central account takeover chain therefore extends well past the initial server compromise, reaching into every downstream device the platform manages.

Exploitation status

N-able confirms this N-central account takeover flaw is being exploited in the wild. The company says a limited number of customers have been identified and directly contacted by support.

Affected versions and patch

All N-central servers running versions prior to 2026.3.1.7 are affected. N-able strongly encourages any customer not on the latest build to upgrade immediately. Full details, including indicators of compromise, are available in N-able’s security update from August 2, 2026. The company also recommends enforcing multi-factor authentication and auditing user access as ongoing protection.

Related coverage

  • Critical Wazuh Vulnerability Enables Lateral Movement and Root Access
  • ImageMagick Flaw Risks Arbitrary Memory Disclosure via PSX TIM File Integer Overflow on 32-bit Systems
  • CERT Warns of Privilege Escalation Vulnerability in Lakeside SysTrack (CVE-2025-6241)
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Stay Ahead of the Threat

Join security professionals receiving zero-hour CVE alerts, PoC updates, and threat analysis directly to their inbox.

No spam. One actionable email per week. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Account Takeover Authentication Bypass CVE-2026-18577 exploited in the wild MSP Security N-able N-central RMM security

Leave a Reply Cancel reply

You must be logged in to post a comment.

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-51990
    A critical remote code execution vulnerability in Sogou Input Method, one of the most widely used Chinese-language input...
    Admin intel📅 Updated: Sep 12, 2026
  • CVE-2026-85706CVSS 10.0
    GitLab has remediated an issue that, under certain conditions, an unauthenticated user could have read arbitrary files from...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intelCISA KEV📅 Added to KEV: Sep 11, 2026📅 Updated: Sep 11, 2026
  • CVE-2026-84869CVSS 9.9
    A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote...
    CISA KEV📅 Added to KEV: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-90608CVSS 9.9
    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element...
  • CVE-2026-90607CVSS 9.9
    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function...
  • CVE-2026-90606CVSS 9.9
    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue...
  • CVE-2026-90605CVSS 9.9
    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects...
  • CVE-2026-81648CVSS 10.0
    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply...
  • CVE-2026-90558CVSS 9.8
    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting...
  • CVE-2026-78159CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-78006CVSS 9.8
    The The Events Calendar plugin for WordPress is vulnerable to Remote Code...
  • CVE-2026-85681CVSS 9.8
    The WP Component WordPress plugin through 2.2.4 does not have any capability...
  • CVE-2026-84171CVSS 9.8
    The WP images upload on piclect WordPress plugin through 1.0 does not...
Powered by CVE WATCHTOWER

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.