CISA has added a fresh N-able N-central vulnerability to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and a second exploitation path forced an emergency hotfix within days of the first patch.
N-able, whose N-central platform is widely used by managed service providers to remotely monitor and manage client networks, disclosed that customers running versions prior to 2026.2 were affected by an authentication bypass issue tracked as CVE-2026-18577. The vulnerability lets an attacker reach protected functionality through an alternate path or channel, without needing valid credentials.
A Second Bypass Found Mid-Response
N-able had already shipped a fix in version 2026.3 and was recommending that customers on older builds upgrade as an immediate protective step. During the follow-up investigation, the company's engineering and security teams identified an alternative way to exploit the same underlying issue that the original patch had not closed off. A hotfix for 2026.3 followed within the same week.
The pattern echoes what CISA has been warning about more broadly this year: remote management and edge infrastructure — the very tools used to administer other systems — have become a preferred entry point for attackers precisely because compromising one credential or platform instance can cascade across every downstream client network it touches.
Why This Matters for African MSPs and IT Providers
Managed service providers and IT consultancies across the region increasingly rely on remote monitoring and management tooling to support clients across multiple sites. A single unpatched RMM instance sitting on the internet can function as a master key into every business it manages, which is exactly the profile CISA's Known Exploited Vulnerabilities catalog is designed to flag: confirmed real-world exploitation, not theoretical risk.
Confirm Your RMM Stack Isn't Exposed
If your business or your provider runs N-central, or any other remote management platform, an independent external scan will confirm what's actually reachable from the internet today. VUNVAULT can map your exposed attack surface and verify patch status before an attacker does.
Request a Scan