Active Exploitation of Critical N-central Authentication Bypass Vulnerability
Exploitation of CVE-2026-18577 could allow an attacker to bypass authentication and lead to administrative account takeover
Summary
Exploitation of CVE-2026-18577 could allow an attacker to bypass authentication and lead to administrative account takeover
Affected platforms
The following platforms are known to be affected:
Threat details
Exploitation of CVE-2026-18577
N-able has observed exploitation of CVE-2026-18577, leading to account takeover and full administrative access to the N-central server.
The NHS England National CSOC assesses further exploitation as likely.
Introduction
N-able has released a security update for N-central to address an incomplete patch for CVE-2026-18556; this issue has been assigned CVE-2026-18577.
- CVE-2026-18556 - Authentication Bypass Using an Alternate Path or Channel vulnerability - CVSSv4 base score: 8.2
- CVE-2026-18577 - Authentication Bypass Using an Alternate Path or Channel vulnerability - CVSSv4 base score: 8.2
Remediation advice
Affected organisations are strongly encouraged to review N‑central Security Update – August 2, 2026 and apply the relevant update as soon as possible.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 3 August 2026 12:17 pm