N-able N-central CISA KEV: Patch CVE-2026-18556 and CVE-2026-18577
August 2, 2026
CISA has added two related N-able N-central authentication-bypass issues to its Known Exploited Vulnerabilities catalog: CVE-2026-18556 and CVE-2026-18577. N-able’s supported server remediation is N-central 2026.3 Hotfix 1, build 2026.3.1.7. Treat this as a priority management-system change: patch the N-central server, validate the control plane, then schedule any agent work separately.
Why this needs prompt attention
CISA identifies both CVEs as actively exploited. CVE-2026-18556 affects N-central releases through 2026.1. CVE-2026-18577 is an incomplete-patch issue affecting releases through 2026.3.1. Both can enable authentication bypass; the later issue can also lead to account takeover. The vendor hotfix addresses the current server-side risk.
Who should act
Review every N-central server, especially externally reachable management systems and instances used to administer customer environments. N-able’s August 2 release notes identify build 2026.3.1.7 as the Hotfix 1 build. Confirm the server build in the product’s normal administration view before opening the emergency change.
Patch the N-central server first
- Open an emergency maintenance change with a clear owner, rollback decision point, and customer-impact contact.
- Use the existing documented N-central recovery procedure. Do not substitute an untested archive for a tested recovery plan during an urgent change.
- Follow N-able’s supported upgrade path for the installed server release, then apply 2026.3 Hotfix 1 to reach build 2026.3.1.7.
- Keep normal management access restricted to approved administrators while the work is in progress. Use established access controls and maintenance communications.
- After the update, validate the administration console, service health, a small representative set of device check-ins, monitoring, and authorized remote-management workflows.
Do not turn an emergency server fix into a fleet-wide change
N-able’s hotfix guidance focuses on the N-central server. The release notes also note a larger Windows Agent installer. Finish the server remediation and validation first, then plan agent and probe upgrades in staged groups under the normal maintenance process. That keeps a security response from creating avoidable bandwidth or support impact across a managed fleet.
Review access after the hotfix
Use your normal incident and change-review process to look for unexpected privileged accounts, unusual administrator activity, unapproved remote-management changes, and alerts that need escalation. Preserve relevant evidence under your retention policy and contact N-able support or your incident-response provider when a review identifies suspicious activity. A hotfix does not, by itself, answer whether an earlier compromise occurred.
Operational checklist
- Record the pre-change and post-change N-central server builds.
- Verify recovery readiness through the existing documented process.
- Apply the supported server hotfix and confirm build 2026.3.1.7.
- Validate core control-plane health before changing agents or probes at scale.
- Review privileged access and management changes with the appropriate security owner.
- Give affected customers a concise maintenance and follow-up status.
Keep the wider support estate current
Managed service teams often maintain WordPress sites alongside infrastructure tooling. Keep site-owner update windows, access review, and recovery procedures current through our WordPress support guides. That is separate work from this N-central server update, but the same disciplined change process matters.

