漏洞描述
N-able N-central versions through 2026.3.1 contain an authentication bypass that lets a remote unauthenticated attacker take over an administrator account and gain full control of the N-central server. CVE-2026-18577 is a bypass of the incomplete fix for CVE-2026-18556, so the 2026.3.1 Hotfix 1 build (2026.3.1.7) does not fully remediate it. Hotfix 2 (2026.3.1.10) supersedes Hotfix 1 and is the first fully fixed 2026.3 build.
影响产品
暂无结构化产品信息。
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
www.n-able.comhttps://www.n-able.com/blog/n-central-security-update-august-6-2026↗status.n-able.comhttps://status.n-able.com/2026/08/06/n-central-2026-3-hotfix-2-additional-mitigation-for-cve-2026-18577/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18577↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-18556↗