← Back to CVE List
Vulnerability Intelligence Report
Incomplete patch leads to administrative account takeover

CVE-2026-18577

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
8.2
HIGH
EPSS Probability:2.53%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-288 ↗CWE-288 Authentication bypass using an alternate path or channel

Affected Products & Versions

Vendor Product Affected Versions
N-able N-central 0 <= 2026.3 (affected), 2026.3.1.7 (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
2.529%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityN-able · Vendor · USA
Reserved2026-08-02T13:40:02
Published2026-08-02T22:06:18
Patch Date2026-08-02
Last Updated2026-08-04T13:32:51

LINK COPIED TO CLIPBOARD