N-able patched an auth bypass in N-central. The patch was incomplete, and attackers came back through the same door
2026-08-09Security
CVE-2026-18577 exists because the fix for CVE-2026-18556 didn't finish the job. Both are being exploited, and N-central sits at the top of MSP estates — admin on the server means Take Control access to every endpoint underneath it.