Skip to content

security_identifier

CVE-2026-18577

Identifier for an authentication bypass and account takeover flaw in N-able N-central arising from an incomplete fix for CVE-2026-18556; listed in CISA's Known Exploited Vulnerabilities catalog.

Current clusters

security5 publishers

CVE-2026-86218 gives unauthenticated attackers code execution on N-able N-central consoles

N-able shipped N-central 2026.3 HF4 on Saturday and says nothing confirms production exploitation, while Huntress calls the bug a possible zero-day and has one compromised customer console whose logs had already rotated.

Perspective Coverage

4 publishers
Builder
Builder 13%
Operator
Operator 66%
Investor
Investor 21%

Reality

Evidence68
Adoption58
Hype gap+15
Incentives62
Confidence74