HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Active Exploitation of N‑able N‑central Authentication Bypass (CVE‑2026‑18577) Added to CISA KEV Catalog

CISA has listed CVE‑2026‑18577, an authentication‑bypass flaw in N‑able N‑central, in its Known Exploited Vulnerabilities catalog, confirming active attacks. Organizations must remediate quickly to maintain SOC 2 access‑control compliance and preserve audit evidence.

LiveThreat™ Intelligence · 📅 August 04, 2026· 📰 cisa.gov
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
cisa.gov

CVE‑2026‑18577 N‑able N‑central Authentication Bypass Using an Alternate Path or Channel

What It Is — A newly disclosed authentication‑bypass flaw in N‑able N‑central that allows an attacker to obtain full control of the management console via an undocumented access path.

Exploitability — Actively exploited in the wild; CISA has placed it in the Known Exploited Vulnerabilities (KEV) Catalog, indicating confirmed malicious use.

Affected Products — N‑able N‑central (all supported versions at the time of disclosure).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access Controls (CC6.1‑CC6.4) – The bypass directly undermines logical‑access safeguards that must be demonstrated during a SOC 2 audit.
  • Continuous Control Monitoring – Rapid detection and remediation provide audit‑ready evidence that the organization follows a risk‑based vulnerability‑management program.
  • Defensible Audit Trail – Documented patching, verification of access‑control remediation, and evidence of post‑remediation testing satisfy both internal governance and external auditor expectations.

Recommended Actions

  • Prioritize patching CVE‑2026‑18577 per vendor guidance and verify remediation on all N‑central instances.
  • Conduct an immediate access‑control review: confirm that only authorized accounts can reach the management console and that MFA is enforced.
  • Capture remediation tickets, patch‑deployment logs, and post‑remediation test results as SOC 2 evidence.
  • Update your vulnerability‑management policy to flag any future KEV entries for accelerated handling.

Source: CISA Advisory – Known Exploited Vulnerabilities Catalog, 2026‑08‑03

📰 Original Source
https://www.cisa.gov/news-events/alerts/2026/08/03/cisa-adds-one-known-exploited-vulnerability-catalog

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →