Advisories
CISA Adds New KEV: N‑Central Authentication Bypass Exploited
CISA has just added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog after confirmed real‑world exploitation. The flaw lets attackers bypass authentication in N‑Central via an alternate path, granting full control of the asset. Federal agencies are now required to patch it immediately under BOD 26‑04, and any organization should treat it as a top‑priority fix. CISA is also calling on the community to submit other actively exploited CVEs for catalog inclusion.
In a swift move, the Cybersecurity and Infrastructure Security Agency (CISA) has appended a fresh entry to its Known Exploited Vulnerabilities (KEV) catalog: CVE‑2026‑18577. This bug, found in N‑Able’s N‑Central platform, permits attackers to sidestep authentication by leveraging an alternate channel, effectively handing them full control of the compromised system.
Why It Matters
- Confirmed active exploitation in the wild.
- Gives attackers unrestricted access to the asset.
- Targets a widely deployed enterprise monitoring solution.
Federal Response
- Binding Operational Directive 26‑04 now mandates rapid remediation of KEV‑listed CVEs on publicly exposed assets.
- FCEB agencies must verify whether a system has been compromised before applying patches.
- Lower‑risk vulnerabilities can be deferred, but KEV entries cannot.
What You Should Do
- Check if your environment runs N‑Central and whether the patch is applied.
- Prioritize the fix in your vulnerability management queue.
- Review other KEV entries and adjust your patching schedule accordingly.
- Report any other actively exploited CVEs via CISA’s KEV Nomination Form.
"CISA will continue to expand the catalog with any CVE that meets the criteria of active exploitation and clear mitigation guidance," the agency noted.