MEDIUMVulnerability
Global

N-able warns of N-central auth bypass flaw exploited in attacks

·Source: BleepingComputer

Updated:

Executive Summary

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

Analysis

N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. [...]

Indicators of Compromise (1)

CVE (1)
CVE-2026-18577
Source Attribution

Originally published by BleepingComputer on Aug 3, 2026.

Related Threats

HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-67611 — OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allow...

OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication by exploiting the exposed OAuth2 password grant flow through an unauthenticated client registration endpoint. Attackers can register an OAuth2 client via the unauthenticated registration endpoint and use the password grant to exchange credenti

CVE-2026-67611
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-67610 — OpenEMR through 8.2.0 contains an improper authentication vulnerability in the O...

OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticated attackers to register a malicious client with system-level FHIR scopes by supplying a self-generated RSA keypair via the jwks field. Once an administrator approves the registered client, attackers can use the client_credentials grant with a self-sig

CVE-2026-67610
NIST NVD
HIGHVulnerabilityNEW

NVD HIGH: CVE-2026-41453 — Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the lead...

Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers can exploit this flaw using time-based and bo

CVE-2026-41453
NIST NVD