Knox CVE Database
/
CVE-2026-18577
High
8.1

CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.

Added to the CISA KEV catalog:
August 3, 2026

Overview

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Vulnerability details

Affected vendor
N-able
Affected product
N-central
Weakness type (CWE)
CWE-288

CVE-2026-18577 is an authentication bypass via an alternate path or channel (CWE-288) in N-able N-central, a widely deployed managed services platform. The original vulnerability, CVE-2026-18556, was patched in Hotfix 1, but that fix was incomplete: at least one alternate authentication path or channel remained accessible, allowing the normal credential-checking mechanism to be circumvented entirely. CWE-288 flaws arise when a product enforces authentication on its primary interface but leaves secondary paths, endpoints, or channels unguarded, and incomplete patches are a common source of such residual exposure.


An attacker with network access to an N-central instance sends crafted requests to the alternate authentication path, bypassing credential validation and gaining full remote administrative access without supplying valid credentials. From that position, the attacker can take over accounts, use N-central's Take Control feature to connect to managed endpoints, and install Cloudflare tunnel services on those devices to maintain persistence even after N-central access is revoked. No prior privileges are required, though the CVSS vector reflects high attack complexity, suggesting the alternate path is not trivially obvious. N-central instances reachable from the internet or an attacker-controlled network are at risk.

Severity and impact

8.1
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
High

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • On managed endpoints, check each user's Documents folder for a file named 'svchost.exe' and audit installed Windows services for a registered service named 'Cloudflared'; either finding indicates post-exploitation persistence from this attack chain.
  • Review N-central audit logs for administrative sessions, account changes, or Take Control activations that have no corresponding authenticated login event, which would indicate the authentication bypass was used to obtain access.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 6, 2026

Additional hardening

  • Restrict network access to the N-central management interface to known administrator IP ranges; internet-facing exposure directly increases risk given the unauthenticated remote access vector.
  • For self-hosted instances, place N-central behind a VPN or zero-trust access gateway so the management plane is not reachable from arbitrary external hosts.
  • Audit managed endpoints for unexpected Cloudflare tunnel services and unauthorized svchost.exe files in user profile directories as part of forensic triage, per vendor guidance.
  • Apply Hotfix 2 (build 2026.3.1.10), which supersedes Hotfix 1 and addresses the related attack path identified after the initial patch; hosted instances receive this automatically.

Key dates

Published (NVD)
August 2, 2026
Added to CISA KEV
August 3, 2026
Remediation deadline
August 6, 2026
Last updated
August 4, 2026

References

Frequently asked questions

Does CVE-2026-18577 affect my FedRAMP authorization?

If N-able N-central runs inside your authorization boundary, yes — CVE-2026-18577 applies directly to your FedRAMP posture. CISA has listed this vulnerability in the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of August 6, 2026. An unpatched KEV within your boundary is an assessor finding: you either remediate it or formally document a mitigation before your sponsoring agency raises it during review.

How does Knox help me handle CVE-2026-18577?

Remediating N-able N-central is your responsibility under the FedRAMP shared-responsibility model — Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary to remediate within, plus Knox's automated continuous monitoring platform and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; maintaining a compliant posture while you do it is not something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues, including CVE-2026-18577. That means exposure surfaces during ongoing monitoring rather than waiting until an assessor flags it at scheduled review, giving your team time to act before a finding becomes a formal problem.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-18577 isn't remediated by August 6, 2026?

Missing the August 6, 2026 deadline turns CVE-2026-18577 into a Plan of Action and Milestones (POA&M) item. A growing POA&M list is what converts a routine continuous-monitoring review into a difficult conversation with your sponsoring agency. Meeting the deadline keeps your authorization intact.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting