An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
https://www.helpnetsecurity.com/2026/08/10/cve-2026-18577-n-central-hotfix-2-msps/
https://www.databreachtoday.com/china-linked-hackers-use-n-able-flaw-in-ransomware-attacks-a-32506
https://therecord.media/china-hackers-ransomware-microsoft
https://thehackernews.com/2026/08/china-linked-hackers-deploy-new.html
https://thehackernews.com/2026/08/n-central-attackers-reach-managed.html
https://www.securityweek.com/cisa-warns-of-exploited-langflow-n-central-and-tomcat-vulnerabilities/
https://thehackernews.com/2026/08/cisa-flags-langflow-rce-tomcat-and-n.html
https://www.sophos.com/en-us/blog/nable-ncentral-exploitation-results-in-rmm-tool-deployment
https://thehackernews.com/2026/08/cisa-adds-exploited-n-able-n-central.html
https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/
https://www.helpnetsecurity.com/2026/08/03/cve-2026-18577-n-able-n-central-vulnerability/
https://www.databreachtoday.com/n-able-flaw-exposes-msps-to-worst-case-scenario-a-32397
https://www.darkreading.com/vulnerabilities-threats/attackers-exploit-n-able-patch-bypass-flaw
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
https://hackread.com/hackers-exploit-n-able-n-central-flaw-initial-fix/
https://www.n-able.com/blog/n-central-security-update-august-2-2026
Published: 2026-08-02
Updated: 2026-08-04
Known Exploited Vulnerability (KEV)
Base Score: 7.6
Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 8.1
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.2
Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L
Severity: High
EPSS: 0.02529
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability of Interest