Skip to main content

Active Exploitation of Critical N-central Authentication Bypass Vulnerability

Exploitation of CVE-2026-18577 could allow an attacker to bypass authentication and lead to administrative account takeover

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Exploitation of CVE-2026-18577 could allow an attacker to bypass authentication and lead to administrative account takeover


Affected platforms

The following platforms are known to be affected:

Threat details

Exploitation of CVE-2026-18577

N-able has observed exploitation of CVE-2026-18577, leading to account takeover and full administrative access to the N-central server.

The NHS England National CSOC assesses further exploitation as likely.


Introduction

N-able has released a security update for N-central to address an incomplete patch for CVE-2026-18556; this issue has been assigned CVE-2026-18577.

  • CVE-2026-18556 - Authentication Bypass Using an Alternate Path or Channel vulnerability - CVSSv4 base score: 8.2
  • CVE-2026-18577 - Authentication Bypass Using an Alternate Path or Channel vulnerability - CVSSv4 base score: 8.2

Threat updates

Date Update
7 Aug 2026 Hotfix 2 – Additional Mitigation for CVE-2026-18577

The follow sections have been updated:

  • Remediation
  • Definitive source of threat updates

Remediation advice

N‑central has released Hotfix 2 – Additional Mitigation that supersedes the earlier release and introduces further security hardening measures to mitigate the risk of exploitation. Affected organisations are strongly encouraged to review N-central 2026.3 Hotfix 2 – Additional Mitigation for CVE-2026-18577 and apply the update as soon as possible.



Last edited: 7 August 2026 12:19 pm