CVE-2026-18577
HIGH KEVN-able N-central - Incomplete Patch Leads to Administrative Account Takeover
Title source: ruleExploitation Summary
CVE-2026-18577 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 3, 2026. EIP tracks 2 public exploits from researchers including CreamyG31337, HORKimhab.
AI-analyzed exploit summary This repository provides a read-only PowerShell-based hunting tool for detecting post-exploitation artifacts related to CVE-2026-18577 and CVE-2026-18556 in N-able N-central. The script checks for indicators of compromise (IoCs) such as rogue Cloudflare Tunnel services, suspicious service paths, and Take Control log artifacts without modifying system state.
Description
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Exploits (2)
This repository provides a read-only PowerShell-based hunting tool for detecting post-exploitation artifacts related to CVE-2026-18577 and CVE-2026-18556 in N-able N-central. The script checks for indicators of compromise (IoCs) such as rogue Cloudflare Tunnel services, suspicious service paths, and Take Control log artifacts without modifying system state.
The repository contains no actual exploit code, technical details, or vulnerability analysis for CVE-2026-18577. It only includes a README with generic setup instructions, donation requests, and legal disclaimers, alongside a .gitignore file and a custom license.
References (5)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H