An incomplete fix puts the same product back in KEV - authentication bypass in N-able N-central (CVE-2026-18577)
An authentication bypass using an alternate path or channel in the IT management software N-able N-central has been added to CISA's Known Exploited Vulnerabilities catalog. CISA states it is the result of an incomplete patch for an earlier CVE.
Key facts
- CVE IDCVE-2026-18577
- Affected (vendor / product)N-able N-central
- CWECWE-288
- ExploitationListed in CISA KEV (exploitation confirmed)
- Remediation due2026-08-06 (U.S. federal civilian agencies, BOD 22-01)
Key points
- Authentication bypass using an alternate path or channel (CWE-288) leads to bypass and account takeover.
- CISA states explicitly that it results from an incomplete patch for CVE-2026-18556.
- Danger remains even where the earlier fix was applied, so a ledger marking it handled no longer matches reality.
- Of the 1,687 KEV records this site holds as of 2026-09-02, four name an incomplete patch in the description.
- The due date is three days after addition; only 86 of the 1,687 carry a three-day deadline.
- IT management software reaches many customer environments, which reads as the background to the short deadline.
1What was supposed to be fixed was not fixed through
That CISA writes "the result of an incomplete patch" for an earlier CVE is the heart of this record. A vulnerability was published, the vendor issued a fix, users applied it - and afterwards the same weakness was found to hold by another route.
From the user side this is awkward. Where applying the earlier update was recorded as done, that ledger no longer matches reality. Reappearing in KEV is what signals the mismatch from outside.
2Four records name an incomplete patch
Four of 1,687 are named in the description as the result of an incomplete patch. That does not mean only four incomplete patches exist: it counts the times CISA wrote it. Incompleteness usually surfaces as the next vulnerability under a new CVE number, and the relationship does not always survive in text.
3The weight of three days
- 1Added to KEV3 August 2026
- 2Due date6 August 2026, three days later
- 3What that meansAgainst 1,025 records at twenty-one days, only 86 carry three
- 4WhyThe flaw leads directly to authentication bypass and account takeover
IT management software like N-central sits where it reaches many customer environments. Bypassing its authentication can carry through to everything it manages, which reads as the background to a short deadline. Four records this site holds as of 2026-09-02 concern N-able.
Why it matters
Managing vulnerabilities as "handled because the fix was applied" breaks down when the fix was incomplete. A vulnerability ledger has to track not only whether an update was applied but whether a follow-up on the same weakness has appeared since. For products reaching many environments, one authentication bypass carries widely, and the short deadline is itself material for prioritisation.
FAQ
What does an incomplete patch mean here?
Is applying the earlier update enough?
Why is the deadline three days?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).