
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for a prior vulnerability, CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication controls and take over user accounts, including administrative accounts, on affected N-central instances. All N-central versions through 2026.3.1 are affected; version 2026.3.1.7 is listed as unaffected. The vulnerability was disclosed on August 2, 2026, and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 score of 8.2 (High) (NVD, GitHub Advisory, CISA KEV).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the patch applied for CVE-2026-18556 closed one authentication path but left an alternate path or channel unprotected, allowing attackers to circumvent authentication entirely. Exploitation requires no privileges, no user interaction, and is conducted over the network, though attack complexity is rated High, suggesting some precondition or non-trivial technique is involved (e.g., specific request crafting or timing). The vulnerability enables full account takeover of N-central administrative accounts without valid credentials. Horizon3.ai published technical research covering both CVE-2026-18556 and CVE-2026-18577, and Rapid7 published an exploitation-in-the-wild analysis (Rapid7 ETR, Horizon3.ai).
Successful exploitation grants an unauthenticated attacker full administrative control over the N-central Remote Monitoring and Management (RMM) console — colloquially described as "god mode" access — enabling them to manage, deploy software to, and execute commands on all endpoints managed by the affected N-central server. Because N-central is used by Managed Service Providers (MSPs) to manage customer networks, a single compromised N-central instance can serve as a launchpad for supply-chain-style attacks against all downstream managed endpoints. Confirmed post-exploitation activity includes deployment of RMM tunneling tools, credential theft via Mimikatz, and ransomware deployment (StormEncryptor) across managed customer environments (BleepingComputer, The Register, Sophos).
CVE-2026-18577 is actively exploited in the wild and was added to CISA's KEV catalog on August 3, 2026, with a federal agency remediation deadline of August 6, 2026 (CISA KEV). The China-linked threat actor Storm-1175 (a former Medusa ransomware affiliate) has been attributed to exploitation of this vulnerability, deploying the new StormEncryptor ransomware against MSP targets (The Hacker News, BleepingComputer). A GitHub repository (HORKimhab/CVE-2026-18577) exists but contains only boilerplate placeholder content with no functional exploit code; however, real-world exploitation is confirmed by multiple vendors and threat intelligence sources. The EPSS score is approximately 4.1%, and CISA's SSVC assessment rates exploitation as active, automatable, and of total technical impact (GitHub Advisory, NVD). Mullvad VPN exit nodes were reportedly observed in exploitation traffic (CybersecurityBoard).
.stormenc or similar extensions on encrypted files); Mimikatz or credential dumping tool artifacts on compromised systems.N-able released Hotfix 1 (version 2026.3.1.7) on August 2, 2026, and subsequently released Hotfix 2 on August 6, 2026, as attackers continued to exploit the vulnerability despite the first patch. Hotfix 2 supersedes Hotfix 1 and should be applied immediately. CISA mandated federal agencies apply mitigations by August 6, 2026 under BOD 26-04. Organizations should: (1) apply N-central Hotfix 2 (2026.3.1.10 or later) immediately; (2) review N-central audit logs for signs of unauthorized access; (3) audit all managed endpoints for unauthorized RMM agent installations or other persistence mechanisms; (4) restrict N-central management interface access to trusted IP ranges where possible (N-able Status HF1, N-able Status HF2, N-able Blog, CISA KEV).
N-able confirmed that attackers successfully reached managed customer endpoints via the vulnerability, acknowledging real-world impact in a vendor statement covered by The Register (The Register). The security community widely characterized the flaw as granting "god mode" access to MSP infrastructure, with ThreatLocker, Arctic Wolf, Rapid7, Beazley Security Labs, and eSentire all publishing advisories or technical analyses. Microsoft attributed exploitation to Storm-1175, a China-linked threat actor and former Medusa ransomware affiliate, which deployed the new StormEncryptor ransomware via compromised N-central instances (The Hacker News). Reddit communities (r/Nable, r/msp, r/sysadmin) saw significant discussion from MSP operators urgently seeking guidance, and analyst price targets for N-able (NYSE: NABL) were reportedly reduced following the incident (SimplyWallSt).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."