Legacy Core™
Official Guidance

CISA adds N-able N-central vulnerability to the KEV Catalog

CISA added CVE-2026-18577, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 3, 2026.

Official source
Cybersecurity and Infrastructure Security Agency
Jurisdiction
United States
Publication date
August 3, 2026
Legacy Core review
August 4, 2026 · Christopher Green
Source checked
August 4, 2026
Affected sectors
Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
Deadline date
August 6, 2026

Summary

CISA added CVE-2026-18577, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 3, 2026.

Why it matters

Small businesses that use N-central directly or through a managed service provider should confirm whether their environment is affected. Catalog inclusion means CISA has evidence of active exploitation; it does not establish that every organization uses the product or has been compromised.

Recommended action

Ask your internal IT owner or managed service provider whether N-central is present, which version is running, and whether the vendor mitigation has been applied. Keep the response with your security-maintenance records.

CISA adds N-able N-central vulnerability to the KEV Catalog — Legacy Core Intelligence | Legacy Core