
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for the previously disclosed CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication mechanisms and take over user accounts, including administrative accounts, on affected N-central instances. The vulnerability affects N-central versions through 2026.3.1, with version 2026.3.1.7 confirmed as unaffected. It was published on August 2, 2026, and carries a CVSS v4.0 base score of 8.2 (High), assigned by N-able (GitHub Advisory, CISA KEV).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning the product requires authentication but exposes an alternate path or channel that does not enforce it (GitHub Advisory). The original patch for CVE-2026-18556 failed to address all authentication bypass vectors, leaving an alternate code path exploitable by unauthenticated network attackers. Exploitation requires no privileges, no user interaction, and no special attack requirements, though attack complexity is rated High, suggesting some non-trivial conditions must be met (e.g., specific request crafting or timing). Security researchers have described the flaw as granting attackers "god mode" access to the N-central RMM console (ixuvo.com, ThreatLocker Blog).
Successful exploitation allows an unauthenticated attacker to fully take over N-central administrative accounts, gaining unrestricted access to the RMM (Remote Monitoring and Management) console. Because N-central is used by Managed Service Providers (MSPs) to manage customer endpoints, a compromised N-central server can serve as a pivot point for supply-chain-style attacks against all managed customer environments — enabling lateral movement, data exfiltration, ransomware deployment, and persistent access across potentially thousands of downstream endpoints (BleepingComputer, Dark Reading, Decryption Digest).
CVE-2026-18577 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026, with a remediation due date of August 6, 2026 (CISA KEV). N-able confirmed that attackers successfully took over N-central servers and reached managed customer endpoints via the flaw (BleepingComputer). Reports indicate Mullvad VPN exit nodes were observed in exploitation activity, suggesting deliberate attacker anonymization (cybersecurityboard.com). The EPSS score is approximately 1.48% (71st percentile), and no specific threat actor attribution has been publicly confirmed. No public proof-of-concept exploit code has been officially confirmed, though exploitation has been reported by multiple threat intelligence sources (GitHub Advisory, ctipilot.ch).
N-able released N-central version 2026.3.1.7 (Hotfix 1) as the patched release, which addresses the incomplete fix for CVE-2026-18556 (N-able Status, N-able Release Notes). All organizations running N-central versions through 2026.3.1 should upgrade to 2026.3.1.7 immediately. CISA's BOD 22-01 requires federal agencies to remediate this vulnerability by August 6, 2026, and recommends all organizations treat this as a critical priority given active exploitation; if patching is not immediately possible, CISA advises following BOD 26-04 guidance or discontinuing use of the product (CISA KEV). Additionally, organizations should review N-central audit logs for signs of unauthorized access and conduct forensic triage per CISA's guidance.
N-able publicly acknowledged the active exploitation and confirmed that attackers successfully reached managed customer endpoints, characterizing the situation as serious (BleepingComputer, The Hacker News). Security researchers and the community widely described the flaw as granting "god mode" access to MSP infrastructure, with significant concern expressed about the supply-chain implications for downstream managed customers (ThreatLocker Blog, GovInfoSecurity). Arctic Wolf and RedLegg published detailed advisories urging immediate patching, and the story received broad coverage across major security outlets including Dark Reading, BleepingComputer, The Hacker News, and SC World (Arctic Wolf, RedLegg, Dark Reading). Social media discussion on Reddit, Mastodon, and LinkedIn was active, with MSP community members expressing urgency and frustration over the incomplete initial patch (Reddit r/Nable).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"