Actively Exploited Flaw Found in N-able N-central: What SMBs Using Remote Management Tools Need to Know
The US Cybersecurity and Infrastructure Security Agency (CISA) has added a new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, confirming it is being actively used by attackers. The flaw, CVE-2026-18577, affects N-able N-central, an authentication bypass vulnerability that allows attackers to gain access through an alternate path, bypassing normal login controls.
N-able N-central is widely used by managed service providers (MSPs) to remotely monitor and manage client IT systems, which means many Australian small businesses could be exposed indirectly through their IT support provider. Vulnerabilities like this are a common target for cybercriminals because successful exploitation can grant significant control over affected systems, potentially exposing multiple client networks at once.
While CISA's directive requiring rapid remediation applies specifically to US federal agencies, the agency strongly encourages all organisations to review the KEV Catalog and patch known exploited vulnerabilities promptly. Businesses that rely on an MSP for IT support should check with their provider to confirm whether N-able N-central is in use and whether patches have been applied.