N-able security advisory (AV26-769) - Update 1
Actively exploited. At least one CVE in this advisory is listed in the CISA Known Exploited Vulnerabilities catalog — exploitation has been observed in the wild. Treat remediation as urgent.
Serial Number: AV26-769 Date: August 4, 2026 Date: August 4, 2026 As of August 2, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.7 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. On August 3, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18577 to their Known Exploited Vulnerabilities (KEV) Database. Update 1 On August 4, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-18556 to their Known Exploited Vulnerabilities (KEV) Database. 2026.3 HF1 Release Notes N-central 2026.3 Hotfix 1 – Mitigation for CVE-2026-18577 | N-able Status Release Notes | N-able Status CISA KEV:CVE-2026-18577 CISA KEV: CVE-2026-18556
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/n-able-security-advisory-av26-769
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Exploitation confirmedCVE-2026-18577Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 83% of all scored CVEs.
- Exploitation confirmedCVE-2026-18556Already exploited in the wild (CISA KEV) — the prediction phase is over. Patch now. Riskier than 19% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18577 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-18556 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploitedCISA Adds Three Known Exploited Vulnerabilities to Catalogcisa
- criticalexploitedCVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerabilitycisa-kev
- highexploitedCISA Adds One Known Exploited Vulnerability to Catalogcisa
- medium[NEU] [mittel] N-able N-Central: Mehrere Schwachstellen ermöglichen Umgehen von Sicherheitsvorkehrungencert-bund
- unknownexploitedNCSC-2026-0275 [1.00] [M/H] Kwetsbaarheden verholpen in N-able N-centralncsc-nl
- criticalexploitedCVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerabilitycisa-kev
- highexploitedCVE-2026-18577: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover i…nvd
- highexploitedCVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central all…nvd
More from Canadian Centre for Cyber Security
- unknownVeeam security advisory (AV26-777)2026-08-04
- unknownAdobe security advisory (AV26-776)2026-08-04
- unknownMISP security advisory (AV26-775)2026-08-04
- unknownCheckpoint security advisory (AV26-774)2026-08-04
- unknownTenable, Inc. security advisory (AV26-773)2026-08-04