Update: Build 2026.3.1.7 (Hotfix 1), cited previously, is no longer the latest mitigation. N-able released 2026.3 Hotfix 2, build 2026.3.1.10, with additional mitigation. On-premises deployments should install it; hosted deployments were mitigated by N-able.
Risk
CVE-2026-18577 is an authentication bypass that can lead to administrative access. Because N-able reports observed exploitation, remediation should include a compromise assessment rather than patching alone.
Immediate action
- ✓Upgrade on-premises N-central to 2026.3.1.10
- ✓Restrict the management interface to trusted networks or VPN access
- ✓Audit administrators, API tokens, new users, and privilege changes
- ✓Rotate credentials and investigate managed endpoints if suspicious activity is found
If Hotfix 1 is already installed
Do not stop at 2026.3.1.7. Back up according to vendor guidance, install 2026.3.1.10, and verify both the build number and management functions after the change.
