
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central that results from an incomplete patch for the prior vulnerability CVE-2026-18556. It allows unauthenticated remote attackers to bypass authentication controls and take over user accounts, including administrative accounts, on affected N-central instances. All N-central versions through 2026.3.1 are affected; version 2026.3.1.7 (Hotfix 1) and the subsequent Hotfix 2 address the issue. The vulnerability was published on August 2–3, 2026, and carries a CVSS v3.1 base score of 8.1 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, CISA KEV).
The root cause is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel): the original patch for CVE-2026-18556 closed one authentication path but left an alternate path or channel unprotected, allowing attackers to circumvent authentication entirely without credentials. Exploitation is network-based, requires no privileges or user interaction, and has high attack complexity (AC:H), suggesting some precondition or timing element is involved — though in practice exploitation has been widely observed in the wild. The vulnerability enables full account takeover of N-central administrative accounts, which serve as the management plane for managed service provider (MSP) environments (GitHub Advisory, CISA KEV, Rapid7 ETR).
Successful exploitation allows an unauthenticated attacker to take over N-central administrative accounts, effectively gaining "god mode" access to the RMM console and all managed endpoints beneath it. Because N-central is used by MSPs to manage customer networks, a compromised N-central server can serve as a pivot point for lateral movement into every customer environment managed by that MSP — a classic supply-chain attack scenario. Attackers have been confirmed to reach managed endpoints, deploy additional RMM tools for persistence, and in at least one campaign, deploy StormEncryptor ransomware across victim networks (BleepingComputer, The Register, Sophos).
CVE-2026-18577 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 3, 2026, with a federal agency remediation deadline of August 6, 2026 (CISA KEV). The China-linked threat actor Storm-1175 (a former Medusa ransomware affiliate) has been attributed to exploitation of this vulnerability, deploying the new StormEncryptor ransomware against MSP targets (The Hacker News, BleepingComputer). A GitHub repository purporting to contain a PoC was assessed as containing only boilerplate placeholder content with no actual exploit code, though real-world exploitation is confirmed by multiple sources including N-able itself. The EPSS score is approximately 4.1%, and the CVSS v4.0 exploit maturity is rated "ATTACKED" (GitHub Advisory, Feedly). Mullvad VPN exit nodes have been observed in exploitation traffic, suggesting deliberate attacker anonymization (CybersecurityBoard).
N-able released two successive hotfixes to address this vulnerability. Hotfix 1 (version 2026.3.1.7) was released on August 2, 2026, and partially mitigated the issue; however, active exploitation continued, necessitating Hotfix 2 (version 2026.3.1.10), released on August 6, 2026, which supersedes Hotfix 1 and provides additional mitigation. Organizations should apply Hotfix 2 immediately. CISA mandated federal agencies patch by August 6, 2026 under BOD 26-04. N-able also advises monitoring for signs of unauthorized account access and reviewing N-central audit logs for anomalous authentication events. If patching is not immediately possible, consider restricting network access to the N-central management interface to trusted IP ranges (N-able Blog, N-able Status HF1, N-able Status HF2, CISA KEV).
N-able confirmed that attackers successfully reached customer-managed endpoints via the vulnerability, issuing two emergency hotfixes within days of disclosure — an unusually rapid response cycle that underscored the severity of the threat (The Register). Security researchers and the MSP community widely described the flaw as granting "god mode" access to RMM infrastructure, with significant alarm expressed on Reddit's r/Nable and r/msp communities about the supply-chain implications for MSP customers. Sophos published a detailed blog on post-exploitation behavior, noting attackers deployed additional RMM tools to maintain persistence after server access was revoked (Sophos). Microsoft attributed exploitation to Storm-1175, a China-linked threat actor and former Medusa ransomware affiliate, which deployed the new StormEncryptor ransomware via compromised N-central infrastructure (The Hacker News). Arctic Wolf, Rapid7, Horizon3.ai, and Beazley Security all published independent advisories and threat intelligence reports, reflecting broad industry concern (Arctic Wolf, Rapid7 ETR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."