CyberSecurity News
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
AI summary
The US Cybersecurity and Infrastructure Security Agency has added a high-severity security flaw in N-able N-central to its list of known exploited vulnerabilities. This decision was made after reports emerged of the flaw being actively exploited. The vulnerability is related to incomplete patching for a previously identified issue and has a CVSS score of 8.2. It allows for exploitation, although the specific details of the vulnerability's impact are not provided. The addition to the KEV catalog was made in response to customer compromises. The vulnerability is tracked as CVE-2026-18577.
Vulnerabilities mentioned
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

