← Back to blog

CISA Adds Actively Exploited N-able N-central Flaw to KEV Catalog

A high-severity vulnerability in N-able N-central has been added to CISA's Known Exploited Vulnerabilities list after customer compromises. Organizations are urged to apply patches immediately.

TL;DR

  • CISA adds CVE-2026-18577 to its KEV catalog due to active exploitation.
  • The flaw affects N-able N-central and stems from incomplete patching.
  • Exploitation has led to confirmed customer compromises.
  • Organizations should prioritize remediation and validate patch effectiveness.
  • The vulnerability carries a CVSS score of 8.2, indicating high severity.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical flaw affecting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-18577, the vulnerability is linked to incomplete remediation of a previously patched issue and is already being exploited in real-world attacks.

This development highlights ongoing risks from unpatched or inadequately patched systems, especially in managed service provider environments where N-able N-central is widely used. With evidence of active exploitation leading to customer compromises, organizations using the platform are strongly encouraged to verify their patch status and take immediate corrective action.

Vulnerability Details

  • CVE-2026-18577 has a CVSS score of 8.2, classifying it as high severity.
  • It is related to incomplete patching of CVE-2026-18556, suggesting prior mitigation attempts were insufficient.
  • The flaw enables unauthorized access, potentially leading to full system compromise.
  • N-able N-central is a remote monitoring and management tool commonly used by MSPs.

Impact and Recommendations

  • Active exploitation has resulted in confirmed customer breaches, prompting CISA's inclusion in the KEV list.
  • Federal agencies are required to remediate the flaw within set deadlines per CISA guidelines.
  • Private sector organizations should treat this as a high-priority patch regardless of regulatory mandates.
  • Security teams should audit existing N-able installations and confirm that patches are fully applied.
  • Monitoring network traffic for signs of compromise and reviewing access logs is also recommended.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

CISA Adds Actively Exploited N-able N-central Flaw to KEV Catalog — Agent Breach Blog | Agent Breach