CVE-2026-18577
N-central vulnerability analysis and mitigation

Overview

CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for a prior vulnerability, CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication controls and take over user accounts, including administrative accounts, on affected N-central instances. All N-central versions through 2026.3.1 are affected; version 2026.3.1.7 is listed as unaffected. The vulnerability was disclosed on August 2, 2026, and added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026. It carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 score of 8.2 (High) (NVD, GitHub Advisory, CISA KEV).

Technical details

The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the patch applied for CVE-2026-18556 closed one authentication path but left an alternate path or channel unprotected, allowing attackers to circumvent authentication entirely. Exploitation requires no privileges, no user interaction, and is conducted over the network, though attack complexity is rated High, suggesting some precondition or non-trivial technique is involved (e.g., specific request crafting or timing). The vulnerability enables full account takeover of N-central administrative accounts without valid credentials. Horizon3.ai published technical research covering both CVE-2026-18556 and CVE-2026-18577, and Rapid7 published an exploitation-in-the-wild analysis (Rapid7 ETR, Horizon3.ai).

Impact

Successful exploitation grants an unauthenticated attacker full administrative control over the N-central Remote Monitoring and Management (RMM) console — colloquially described as "god mode" access — enabling them to manage, deploy software to, and execute commands on all endpoints managed by the affected N-central server. Because N-central is used by Managed Service Providers (MSPs) to manage customer networks, a single compromised N-central instance can serve as a launchpad for supply-chain-style attacks against all downstream managed endpoints. Confirmed post-exploitation activity includes deployment of RMM tunneling tools, credential theft via Mimikatz, and ransomware deployment (StormEncryptor) across managed customer environments (BleepingComputer, The Register, Sophos).

Exploitability

CVE-2026-18577 is actively exploited in the wild and was added to CISA's KEV catalog on August 3, 2026, with a federal agency remediation deadline of August 6, 2026 (CISA KEV). The China-linked threat actor Storm-1175 (a former Medusa ransomware affiliate) has been attributed to exploitation of this vulnerability, deploying the new StormEncryptor ransomware against MSP targets (The Hacker News, BleepingComputer). A GitHub repository (HORKimhab/CVE-2026-18577) exists but contains only boilerplate placeholder content with no functional exploit code; however, real-world exploitation is confirmed by multiple vendors and threat intelligence sources. The EPSS score is approximately 4.1%, and CISA's SSVC assessment rates exploitation as active, automatable, and of total technical impact (GitHub Advisory, NVD). Mullvad VPN exit nodes were reportedly observed in exploitation traffic (CybersecurityBoard).

Exploitation steps

  1. Reconnaissance: Identify internet-facing N-central RMM servers using tools like Shodan or Censys, targeting instances running versions at or below 2026.3.1. N-central typically exposes a web management interface on standard HTTPS ports.
  2. Identify alternate authentication path: Leverage knowledge of the incomplete patch for CVE-2026-18556 to identify an alternate authentication endpoint or channel that was not covered by the original fix (CWE-288). This may involve probing authentication-adjacent endpoints or API routes that bypass the patched code path.
  3. Craft bypass request: Send a specially crafted HTTP request to the unprotected alternate authentication path, exploiting the missing authentication check to obtain a valid session or administrative token without supplying valid credentials.
  4. Achieve administrative account takeover: Use the obtained session to access the N-central administrative console with full privileges, enabling management of all connected MSP customer endpoints.
  5. Lateral movement to managed endpoints: Deploy RMM tunneling agents or remote access tools (e.g., legitimate RMM software) to managed customer endpoints via N-central's built-in software deployment capabilities, establishing persistence even if N-central server access is later revoked.
  6. Post-exploitation: Execute credential harvesting (e.g., Mimikatz), exfiltrate data, and/or deploy ransomware (StormEncryptor) across managed customer environments (BleepingComputer, Sophos, Rapid7 ETR).

Indicators of compromise

  • Network: Unusual or unauthenticated HTTP/HTTPS requests to N-central authentication endpoints or alternate API paths from unexpected source IPs; outbound connections from the N-central server to unknown external IPs; Mullvad VPN exit node IPs observed in access logs during exploitation (CybersecurityBoard).
  • Logs: N-central access logs showing successful administrative sessions with no corresponding valid login credentials; unexpected account creation or privilege escalation events in N-central audit logs; authentication events from unusual geographic locations or IP ranges.
  • File System: Unexpected RMM agent installers or tunneling tool binaries deployed to managed endpoints via N-central; StormEncryptor ransomware binaries (.stormenc or similar extensions on encrypted files); Mimikatz or credential dumping tool artifacts on compromised systems.
  • Process: Unusual processes spawned by the N-central service account; RMM tools (e.g., ScreenConnect, AnyDesk) installed on endpoints without change management records; credential dumping activity (lsass memory access) on managed endpoints.
  • Persistence: New scheduled tasks or services on managed endpoints installed via N-central deployment; attacker-controlled RMM agents persisting after N-central server access is revoked (Sophos, GitHub IOC Triage).

Mitigation and workarounds

N-able released Hotfix 1 (version 2026.3.1.7) on August 2, 2026, and subsequently released Hotfix 2 on August 6, 2026, as attackers continued to exploit the vulnerability despite the first patch. Hotfix 2 supersedes Hotfix 1 and should be applied immediately. CISA mandated federal agencies apply mitigations by August 6, 2026 under BOD 26-04. Organizations should: (1) apply N-central Hotfix 2 (2026.3.1.10 or later) immediately; (2) review N-central audit logs for signs of unauthorized access; (3) audit all managed endpoints for unauthorized RMM agent installations or other persistence mechanisms; (4) restrict N-central management interface access to trusted IP ranges where possible (N-able Status HF1, N-able Status HF2, N-able Blog, CISA KEV).

Community reactions

N-able confirmed that attackers successfully reached managed customer endpoints via the vulnerability, acknowledging real-world impact in a vendor statement covered by The Register (The Register). The security community widely characterized the flaw as granting "god mode" access to MSP infrastructure, with ThreatLocker, Arctic Wolf, Rapid7, Beazley Security Labs, and eSentire all publishing advisories or technical analyses. Microsoft attributed exploitation to Storm-1175, a China-linked threat actor and former Medusa ransomware affiliate, which deployed the new StormEncryptor ransomware via compromised N-central instances (The Hacker News). Reddit communities (r/Nable, r/msp, r/sysadmin) saw significant discussion from MSP operators urgently seeking guidance, and analyst price targets for N-able (NYSE: NABL) were reportedly reduced following the incident (SimplyWallSt).

Additional resources


SourceThis report was generated using AI

Related N-central vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
YesYesAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
YesYesAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management