securityonline.info
CVE-2026-18577: N-central Account Takeover Exploited in the Wild
TL;DR: Attackers are actively exploiting a N-central account takeover flaw tracked as CVE-2026-18577. N-able says an incomplete patch for an earlier bug left the door open. A hotfix for version 2026.3.1.7 closes the gap. Why it matters N-central is a remote monitoring and management platform used by managed service providers. A N-central account takeover on this platform can cascade into every customer environment it oversees.