CuraSec

Act active

CISA KEV: N-able N-central RMM Actively Exploited (CVE-2026-18577)

2026-08-04 13:07 UTC · The Hacker News · read the source ↗ #cisa-kev#rmm-software#active-exploitation
  • Engineer — Act: CVE-2026-18577 is CISA KEV-listed with a public PoC and confirmed in-the-wild exploitation; if you run N-able N-central, apply the latest patch immediately and treat any N-central host as potentially compromised pending verification.
  • SOC/IR — Act: Confirmed customer compromises via an RMM platform mean privileged agent access may already be weaponized; hunt for anomalous lateral movement or command execution originating from N-central agents since the disclosure date and sweep admin audit logs for unauthorized access.
  • Leader — Act: RMM platforms have privileged access across entire client estates — if your organization uses an MSP that runs N-able N-central, this week confirm whether they are patched and request a written attestation, as confirmed customer compromises indicate active supply-chain risk through managed-service relationships.
  • Signals: CVE-2026-18556 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub · CVE-2026-18577 — CISA KEV: listed, EPSS 0.01, public PoC on GitHub, reported by 2 collected sources
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.