HIGH: N-able N-central Auth Bypass Exploited After Incomplete Patch
N-able confirmed that attackers exploited an authentication bypass in N-central to take over administrator accounts on customer RMM servers, then found its original patch was incomplete. CVE-2026-18577 widens the affected range to every build before 2026.3.1.7, which shipped on August 2. Attackers pivoted from compromised consoles into managed endpoints and planted Cloudflare tunnels that survive both reboots and revoked console access.