CVE-2026-18577
N-central vulnerability analysis and mitigation

Overview

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for the prior vulnerability CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication controls and take over user accounts, including administrative accounts, on affected N-central instances. All N-central versions through 2026.3.1 are affected; version 2026.3.1.7 (Hotfix 1) and the subsequent Hotfix 2 address the issue. The vulnerability was published on August 2–3, 2026, and carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, CISA KEV).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the original patch for CVE-2026-18556 closed one authentication path but left an alternate path or channel unprotected, allowing attackers to circumvent authentication entirely without credentials. Exploitation is network-based, requires no privileges or user interaction, and has high attack complexity (AC:H), suggesting some precondition or timing element is involved — though in practice exploitation has been widely observed in the wild. The vulnerability enables full account takeover of N-central administrative accounts, which serve as the management plane for managed service provider (MSP) environments (GitHub Advisory, CISA KEV, Rapid7 ETR).

Impact

Successful exploitation allows an unauthenticated attacker to take over N-central administrative accounts, effectively gaining "god mode" access to the RMM console and all managed endpoints beneath it. Because N-central is used by MSPs to manage customer networks, a compromised N-central server can serve as a pivot point for lateral movement into every customer environment managed by that MSP — a classic supply-chain attack scenario. Attackers have been confirmed to reach managed endpoints, deploy additional RMM tools for persistence, and in at least one campaign, deploy StormEncryptor ransomware across victim networks (BleepingComputer, The Register, Sophos).

Exploitability

CVE-2026-18577 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026, with a federal agency remediation deadline of August 6, 2026 (CISA KEV). The China-linked threat actor Storm-1175 (a former Medusa ransomware affiliate) has been attributed to exploitation of this vulnerability, deploying the new StormEncryptor ransomware against MSP targets (The Hacker News, BleepingComputer). A GitHub repository purporting to contain a PoC was assessed as containing only boilerplate placeholder content with no actual exploit code, though real-world exploitation is confirmed by multiple sources including N-able itself. The EPSS score is approximately 4.1%, and the CVSS v4.0 exploit maturity is rated "ATTACKED" (GitHub Advisory, Feedly). Mullvad VPN exit nodes have been observed in exploitation traffic, suggesting deliberate attacker anonymization (CybersecurityBoard).

Exploitation steps

  1. Reconnaissance: Identify internet-facing N-central RMM servers using tools like Shodan or Censys, targeting instances running versions through 2026.3.1. N-central servers are commonly exposed on standard HTTPS ports.
  2. Identify alternate authentication path: Leverage knowledge of the incomplete patch for CVE-2026-18556 to identify the alternate authentication channel or endpoint that was not addressed by the original fix (CWE-288).
  3. Authentication bypass: Send a crafted HTTP request to the unpatched alternate authentication path, bypassing credential validation without supplying valid credentials. The high attack complexity (AC:H) suggests this may require specific request crafting or timing.
  4. Account takeover: Upon successful bypass, gain access to an N-central administrative account, achieving full RMM console access ("god mode").
  5. Lateral movement to managed endpoints: Use the N-central administrative access to push commands, scripts, or agents to all managed customer endpoints via the RMM platform's built-in agent management capabilities.
  6. Persistence and payload deployment: Deploy additional RMM tools or remote access agents to maintain persistence even if N-central server access is later revoked. Deploy ransomware (e.g., StormEncryptor) or other malware across managed endpoints (BleepingComputer, Sophos, The Register).

Indicators of compromise

  • Network: Inbound HTTP/HTTPS requests to N-central authentication endpoints from unexpected IP ranges, particularly Mullvad VPN exit nodes; unusual outbound connections from N-central server to unknown external IPs; unexpected RMM agent traffic from managed endpoints to new command-and-control infrastructure.
  • Logs: N-central access logs showing successful authentication events with no corresponding valid credential submission; authentication events from IP addresses not associated with known administrators; bulk agent management commands issued in short succession.
  • File System: Presence of unauthorized RMM agent installers or scripts pushed to managed endpoints; StormEncryptor ransomware artifacts (encrypted files with new extensions) on managed systems; new scheduled tasks or services created on managed endpoints by the N-central agent account.
  • Process: Unexpected processes spawned on managed endpoints via N-central agent (e.g., PowerShell, cmd.exe executing encoded commands); Mimikatz or credential-dumping tool artifacts on compromised systems.
  • Threat Intelligence: A community-maintained IOC triage script for N-central compromise is available at GitHub - ncentral-compromise-ioc-triage (Feedly).

Mitigation and workarounds

N-able released two successive hotfixes to address this vulnerability. Hotfix 1 (version 2026.3.1.7) was released on August 2, 2026, and partially mitigated the issue; however, active exploitation continued, necessitating Hotfix 2 (version 2026.3.1.10), released on August 6, 2026, which supersedes Hotfix 1 and provides additional mitigation. Organizations should apply Hotfix 2 immediately. CISA mandated federal agencies patch by August 6, 2026 under BOD 26-04. N-able also advises monitoring for signs of unauthorized account access and reviewing N-central audit logs for anomalous authentication events. If patching is not immediately possible, consider restricting network access to the N-central management interface to trusted IP ranges (N-able Blog, N-able Status HF1, N-able Status HF2, CISA KEV).

Community reactions

N-able confirmed that attackers successfully reached customer-managed endpoints via the vulnerability, issuing two emergency hotfixes within days of disclosure — an unusually rapid response cycle that underscored the severity of the threat (The Register). Security researchers and the MSP community widely described the flaw as granting "god mode" access to RMM infrastructure, with significant alarm expressed on Reddit's r/Nable and r/msp communities about the supply-chain implications for MSP customers. Sophos published a detailed blog on post-exploitation behavior, noting attackers deployed additional RMM tools to maintain persistence after server access was revoked (Sophos). Microsoft attributed exploitation to Storm-1175, a China-linked threat actor and former Medusa ransomware affiliate, which deployed the new StormEncryptor ransomware via compromised N-central infrastructure (The Hacker News). Arctic Wolf, Rapid7, Horizon3.ai, and Beazley Security all published independent advisories and threat intelligence reports, reflecting broad industry concern (Arctic Wolf, Rapid7 ETR).

Additional resources


SourceThis report was generated using AI

Related N-central vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
YesYesAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
YesYesAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management