CISA Warns: N-able N-central Flaw Actively Exploited, Patch Now
The Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in N-able N-central to its Known Exploited Vulnerabilities catalog, confirming it is being used in real-world attacks. The flaw, tracked as CVE-2026-18577, is rated high severity with a CVSS score of 8.2. It stems from an incomplete fix for an earlier vulnerability, CVE-2026-18556, meaning the original patch did not fully close the security gap.
N-able N-central is widely used by managed service providers (MSPs) and IT teams to remotely monitor and manage devices across client networks. Because these platforms have deep access into customer systems, a compromise can give attackers a foothold to reach many businesses at once. CISA's addition to the KEV catalog follows reports of actual customer compromises linked to this flaw, underscoring that the risk is not theoretical.
Australian businesses that rely on an MSP using N-able N-central should ask their provider whether the latest patches have been applied and confirm the fix fully addresses both CVEs. Given the tool's privileged access to client systems, unpatched instances represent a serious supply-chain risk for any organisation downstream of an affected MSP.