logo

CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV

ID: d2dfe124-b725-55d7-b46e-bf45e7b48077

STIX ID: report--d2dfe124-b725-55d7-b46e-bf45e7b48077

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-04

Date Updated: 2026-08-04

Author: Divya

ADMIRALTY:B6
...
...

**Executive summary:** CISA added CVE-2026-18577 — an actively exploited authentication bypass in N-able N-central — to its Known Exploited Vulnerabilities catalog; attackers have been observed gaining administrative access to N-central instances, abusing the platform’s 'Take Control' functionality and registering persistent Cloudflare Tunnel access, while N-able released a hotfix and flagged versions prior to 2026.3.1.7 as vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.