🟠 High | Source: The Hacker News
CISA has added CVE-2026-18577, a high-severity flaw in N-able N-central (a widely used remote monitoring and management platform), to its Known Exploited Vulnerabilities catalogue following confirmed customer compromises. The vulnerability is an incomplete patch for an earlier flaw (CVE-2026-18556) and carries a CVSS score of 8.2. Because N-central is used by managed service providers to administer client environments, successful exploitation could provide attackers with broad access across multiple downstream organisations.
Security Architect’s Take: If your organisation or any MSP in your supply chain uses N-able N-central, treat this as urgent: verify the current patch level immediately, check for indicators of compromise in N-central audit logs and connected endpoints, and consider restricting N-central’s network exposure to approved management IPs until a confirmed fix is applied.
Original advisory: CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises