CISA Adds the Exploited N-able N-central Flaw (CVE-2026-18577) to Its KEV Catalog

The N-central flaw just went federal. CISA added CVE-2026-18577 (CVSS 8.2) to its Known Exploited Vulnerabilities catalog after N-able found a second vector past the original patch for CVE-2026-18556 — putting federal agencies on the clock and every MSP customer in scope.

Share
Navy duotone documentary: an RMM server rack with one red warning tag — CISA adds the exploited N-able N-central flaw CVE-2026-18577 to its KEV catalog.

The N-able N-central flaw that managed service providers spent last weekend patching is now a federal problem. On Monday, August 3, CISA added CVE-2026-18577 — the authentication-bypass vulnerability in N-able's N-central remote monitoring and management platform — to its Known Exploited Vulnerabilities catalog, the agency's running list of flaws it has confirmed are being used in real attacks.

The listing does two things at once. It starts a remediation clock for federal civilian agencies, and it raises the priority signal for every organization that keys its patching off KEV. What makes this one worth a second look is the lineage behind it: CVE-2026-18577 (CVSS 8.2) is the incomplete patch for an earlier flaw, and attackers found their way past that first fix to gain administrator access to N-central servers.

What CISA Added, and Why It Matters Now

CISA's KEV catalog is not a severity ranking. A vulnerability lands on it when the agency has evidence of active exploitation, which is a higher bar than a bad CVSS score alone. That is the whole point of the list: it separates the flaws attackers are actually using from the far larger pile of theoretical risk. CVE-2026-18577 qualified because N-able and outside responders confirmed the bug was being exploited in the wild, not because of its 8.2 rating.

For N-central specifically, the exploitation path is what earns the urgency. An unauthenticated attacker can bypass the platform's login and take over an administrative account on the server. Because N-central is the console MSPs use to monitor and control the endpoints of every business they support, admin access to the server is a launch point toward those managed customer machines — which is why a single compromised console can put an entire downstream customer base in scope.

The Lineage: One Flaw, an Incomplete Fix, a Second Vector

Rapid7's emergent threat report lays out the sequence that trips people up. The original vulnerability was CVE-2026-18556, also rated CVSS 8.2, and N-able shipped a patch for it. That patch turned out to be incomplete. Attackers found a way around it, and the bypass got its own identifier: CVE-2026-18577. In other words, the second CVE is not a separate, unrelated bug — it is the same authentication weakness reopened through a vector the first fix did not close.

Dark Reading reports that N-able discovered the additional vector over the weekend and that exploiting it hands attackers administrator access to the server. The practical consequence: any operator who applied the earlier fix and assumed the matter was closed may still be exposed. "We already patched" is the reassurance this incident specifically breaks.

CVE Lineage
From original flaw to federal clock
● CVE-2026-18556 (CVSS 8.2)
The original N-central authentication-bypass flaw. N-able ships its first patch.
● CVE-2026-18577 (CVSS 8.2)
The first fix was incomplete. Attackers found the bypass and gained administrator access to N-central servers.
● CISA adds CVE-2026-18577 to KEV — Aug 3, 2026
Active exploitation confirmed. Federal agencies go on a remediation clock; everyone tracking KEV gets the escalation signal.
● Fix: build 2026.3.1.7
The first version N-able says is not affected. Every earlier on-premises build stays exposed until it is upgraded.
Source: CISA KEV catalog and reporting by The Hacker News, Rapid7 and Dark Reading, Aug 3–4, 2026.

We covered the initial disclosure and the mechanics of the patch bypass when N-able confirmed active exploitation: N-able N-central CVE-2026-18577 actively exploited, initial patch bypassed. The KEV addition is the escalation on top of that story — the federal system formally catching up to what the vendor already confirmed.

What MSPs and Downstream Customers Must Verify Now

If you run N-central on-premises, the KEV listing does not change the technical fix — it changes the urgency and, for federal agencies, the obligation. Rapid7's emergent threat report gives the checklist to work through:

  • Confirm you are on build 2026.3.1.7. This is the first version N-able identifies as unaffected. An earlier update, including the incomplete first fix, does not close the exposure — that is the specific trap in this incident.
  • Audit administrative access since roughly July 31. That is around when N-able first noticed something wrong, so it is a reasonable floor for reviewing unexpected admin logins, new or altered accounts, and configuration changes you cannot explain.
  • Assume downstream reach until you can rule it out. Because admin access to the server can extend to managed endpoints, a confirmed server compromise means checking the customer estate, not just the console. Follow Rapid7's ETR guidance for indicators and response steps.
  • Tell affected customers. The businesses you manage cannot act on a risk they have not heard about, and for MSPs the disclosure timing carries both trust and contractual weight.

Patching without hunting for prior access leaves the worse half of the problem unsolved. The upgrade stops further entry; it does nothing about access that already happened during the exploitation window.

The Federal Clock

A KEV listing binds federal civilian executive branch agencies to remediate by a set due date under CISA's standing directive. Reporting from The Hacker News puts the remediation date for this flaw at August 6, 2026 — an unusually compressed window against the roughly 21 days KEV deadlines typically run, which is consistent with CISA shortening the timeline for a flaw already under active attack. Treat that date as reported rather than independently confirmed by us; agencies should follow the due date recorded in the KEV catalog entry itself.

For private-sector defenders, the deadline is not binding, but the signal is. If your patch prioritization keys off KEV, this one has now crossed that threshold — and the vendor's own confirmation of exploitation was already reason enough to move.

Open Questions

Several things the KEV addition does not settle. The number of N-central servers compromised and the count of downstream endpoints attackers reached are still not public. Whether the N-central Cloud tier is affected the same way as on-premises deployments is not confirmed in what has been disclosed. No specific MSP has publicly confirmed a compromise, and the threat actor or actors behind the exploitation are not named.

My read: the KEV listing is confirmation, not new danger — the risk was already real once N-able said the fix had been bypassed. What the federal clock adds is a forcing function and a reason to stop treating this as done. The number that matters is still 2026.3.1.7, and the log review back to July 31 matters as much as the upgrade, because the reach into managed customers is what separates an IT cleanup from a supply-chain incident.

Primary Documents