
CISA Adds Actively Exploited N-able N-central Vulnerability to KEV Catalog
CybersecurityVulnerabilitiesExploitsPatchManagement
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a high-severity vulnerability in N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog on Monday following confirmed active exploitation. The flaw, tracked as CVE-2026-18577 with a CVSS score of 8.2, stems from incomplete patching of a prior vulnerability (CVE-2026-18556, also CVSS 8.2). The exploitation has led to customer compromises, though specific attack vectors or affected organizations were not disclosed. No patch release date or mitigation steps were provided in the notice. The inclusion in the KEV catalog mandates federal agencies to remediate the flaw by a specified deadline.