CISA adds N-able N-central vulnerability to the KEV Catalog
CISA added CVE-2026-18577, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 3, 2026.
- Official source
- Cybersecurity and Infrastructure Security Agency ↗
- Jurisdiction
- United States
- Publication date
- August 3, 2026
- Legacy Core review
- August 4, 2026 · Christopher Green
- Source checked
- August 4, 2026
- Affected sectors
- Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
- Deadline date
- August 6, 2026
Summary
CISA added CVE-2026-18577, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 3, 2026.
Why it matters
Small businesses that use N-central directly or through a managed service provider should confirm whether their environment is affected. Catalog inclusion means CISA has evidence of active exploitation; it does not establish that every organization uses the product or has been compromised.
Recommended action
Ask your internal IT owner or managed service provider whether N-central is present, which version is running, and whether the vendor mitigation has been applied. Keep the response with your security-maintenance records.