By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds N-able N-central Vulnerability to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added a significant security vulnerability affecting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog on Monday. This addition follows numerous reports indicating that the flaw is being actively exploited by malicious actors in real-world cyberattacks. The vulnerability, identified by the identifier CVE-2026-18577, has been assigned a high severity score of 8.2 on the Common Vulnerability Scoring System (CVSS). This specific flaw is a consequence of incomplete patching related to a previously identified vulnerability, CVE-2026-18556, which also carried a CVSS score of 8.2. The incomplete remediation for CVE-2026-18556 created the new vulnerability, CVE-2026-18577, allowing for potential unauthorized access or control.
N-able N-central is a widely used remote monitoring and management (RMM) software solution designed for managed service providers (MSPs). MSPs rely on N-central to remotely manage and secure their clients' IT infrastructure, including servers, workstations, and network devices. The active exploitation of a vulnerability within this critical management tool poses a substantial risk to a broad range of businesses that depend on MSPs for their IT operations. Attackers exploiting this flaw could potentially gain privileged access to the networks of numerous end-user organizations, leading to data breaches, ransomware attacks, or the deployment of other malicious software. The inclusion of CVE-2026-18577 in the KEV catalog mandates that federal agencies remove any identified vulnerabilities from their networks by a specified deadline to mitigate immediate risks.
CISA's KEV catalog serves as a crucial resource for cybersecurity professionals, highlighting vulnerabilities that have been confirmed as actively exploited. Organizations are strongly advised to prioritize patching or mitigating any vulnerabilities listed in this catalog. The presence of CVE-2026-18577 on this list underscores the urgency for N-able and its customers to implement the necessary security updates. While the specific details of the exploitation methods are not fully disclosed by CISA to prevent further misuse, the agency's action signals a clear and present danger. The vulnerability's nature as an incomplete patch for a prior issue suggests a potential oversight in the remediation process, emphasizing the importance of thorough verification after applying security updates. This event highlights the ongoing challenges in securing complex IT supply chains and the critical role of RMM software in the cybersecurity landscape.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.