CVE-2026-18577 is a critical authentication bypass vulnerability in N-able N-central, an RMM platform widely used by MSPs and enterprise IT teams. It emerged as an incomplete fix for a prior vulnerability (CVE-2026-18556) and allows remote unauthenticated attackers to gain full administrative control of N-central servers. Active exploitation has been observed since August 1, 2026, with attackers using the platform's Take Control feature to access managed endpoints and deploying Cloudflare Tunnel (cloudflared) for persistent access. CISA added it to the KEV catalog on August 3, 2026. On-premise deployments must manually apply N-central 2026.3.1 Hotfix 1. IOCs include a suspicious cloudflared service, a rogue svchost.exe in user Documents, and several malicious IP addresses. Rapid7's InsightVM, Nexpose, and Exposure Command customers can scan for exposure using a check released August 4.