N-able has alerted customers to an authentication bypass vulnerability in N-central affecting both hosted and on-premises deployments. The flaw (CVE-2026-18577) is currently being exploited in active attacks.
The vulnerability allows attackers to bypass authentication controls on N-central servers, potentially granting unauthorized access to the remote management platform used by managed service providers.
N-able's warning indicates the flaw affects multiple deployment types, creating risk across its customer base regardless of infrastructure choice. The company has not disclosed specific technical details about the bypass mechanism or the scope of affected versions.
Customers are advised to apply available patches and review access logs for signs of compromise. Organizations using N-central should prioritize patching and monitor for suspicious authentication activity.
N-central is widely deployed in managed IT environments, making this vulnerability significant for MSPs and their end clients. The active exploitation underscores the urgency of remediation.
Additional details on vulnerable versions and remediation steps are available through N-able's security advisories.
A former NSA official has warned against connecting water infrastructure controllers to the internet following suspected Iranian cyberattacks on U.S. water systems.
Security researchers scanning Polish government websites discovered critical vulnerabilities that could expose courts, hospitals, and airports to cyberattacks. The vulnerabilities stem from common software used to manage and display web content.
A critical SQL injection vulnerability in Metabase is being actively exploited in the wild to steal customer data. The zero-day attack has already compromised instances at Framework and Tally.
Healthcare software company Unlimited Technology Systems disclosed a data breach affecting 3.8 million individuals. The breach occurred in October 2025.