Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.

N-able says attackers exploited an N-central authentication bypass to take over servers, reach managed endpoints, and preserve access with Cloudflare

N-able has told customers that attackers broke into servers running its N-central platform, took administrative control without needing a password, and used that access to reach…