Exploited Known exploited (KEV) CVE-2026-18577

An incomplete fix puts the same product back in KEV - authentication bypass in N-able N-central (CVE-2026-18577)

N-able N-central Added to KEV Aug 3, 2026 Federal remediation due 2026-08-06

An authentication bypass using an alternate path or channel in the IT management software N-able N-central has been added to CISA's Known Exploited Vulnerabilities catalog. CISA states it is the result of an incomplete patch for an earlier CVE.

Key facts

  • CVE IDCVE-2026-18577
  • Affected (vendor / product)N-able N-central
  • CWECWE-288
  • ExploitationListed in CISA KEV (exploitation confirmed)
  • Remediation due2026-08-06 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • Authentication bypass using an alternate path or channel (CWE-288) leads to bypass and account takeover.
  • CISA states explicitly that it results from an incomplete patch for CVE-2026-18556.
  • Danger remains even where the earlier fix was applied, so a ledger marking it handled no longer matches reality.
  • Of the 1,687 KEV records this site holds as of 2026-09-02, four name an incomplete patch in the description.
  • The due date is three days after addition; only 86 of the 1,687 carry a three-day deadline.
  • IT management software reaches many customer environments, which reads as the background to the short deadline.

1What was supposed to be fixed was not fixed through

That CISA writes "the result of an incomplete patch" for an earlier CVE is the heart of this record. A vulnerability was published, the vendor issued a fix, users applied it - and afterwards the same weakness was found to hold by another route.

A newly found vulnerabilityThe result of an incomplete patch (this case)
An unknown weakness comes to lightA known weakness was not closed through
Applying the fix addresses itDanger remains even where the earlier fix was applied
Response begins at publicationResponse begins by revising the belief that it was handled

From the user side this is awkward. Where applying the earlier update was recorded as done, that ledger no longer matches reality. Reappearing in KEV is what signals the mismatch from outside.

2Four records name an incomplete patch

KEV records held by this site1,687CISA catalog of exploited vulnerabilities
Descriptions saying "incomplete patch"40.2 per cent of the whole
Records with a three-day due date86this one is among them

Four of 1,687 are named in the description as the result of an incomplete patch. That does not mean only four incomplete patches exist: it counts the times CISA wrote it. Incompleteness usually surfaces as the next vulnerability under a new CVE number, and the relationship does not always survive in text.

3The weight of three days

  1. 1Added to KEV3 August 2026
  2. 2Due date6 August 2026, three days later
  3. 3What that meansAgainst 1,025 records at twenty-one days, only 86 carry three
  4. 4WhyThe flaw leads directly to authentication bypass and account takeover

IT management software like N-central sits where it reaches many customer environments. Bypassing its authentication can carry through to everything it manages, which reads as the background to a short deadline. Four records this site holds as of 2026-09-02 concern N-able.

Why it matters

Managing vulnerabilities as "handled because the fix was applied" breaks down when the fix was incomplete. A vulnerability ledger has to track not only whether an update was applied but whether a follow-up on the same weakness has appeared since. For products reaching many environments, one authentication bypass carries widely, and the short deadline is itself material for prioritisation.

FAQ

What does an incomplete patch mean here?
That the fix the vendor issued for an earlier CVE did not close the weakness through. CISA states this in the description.
Is applying the earlier update enough?
No. Because the fix was incomplete, danger remains even where it was applied. Verify with official vendor information and your own environment.
Why is the deadline three days?
CISA gives no reason, though the flaw leads directly to authentication bypass and account takeover and the product is IT management software.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#KEV#CISA#N-able#authentication bypass#incomplete patch#CWE-288
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.