CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

N-able security advisory (AV26-769) - Update 1

unknownknown exploitedpublic exploitCVE-2026-18577CVE-2026-18556
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-769 Date: August 4, 2026 Date: August 4, 2026 As of August 2, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. On August 3, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577 to their Known Exploited Vulnerabilities (KEV) Database. Update 1 On August 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18556 to their Known Exploited Vulnerabilities (KEV) Database. 2026.3 HF1 Release Notes N-central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577 | N-able Status Release Notes | N-able Status CISA KEV:CVE-2026-18577 CISA KEV: CVE-2026-18556

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-04
Exploitation
Observed in the wild (CISA KEV)

Original advisory: https://cyber.gc.ca/en/alerts-advisories/n-able-security-advisory-av26-769

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-18577coverage & exploitation statusNVD · CVE.org
CVE-2026-18556coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security