CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
2026-08-06T07:23:37Z•1bb5b31201b39c2b6c29800a3689c77b185b78873db5ed1bbf825ac0e875d812
CVE-2026-18556CVE-2026-18577CVE-2026-66066Active StorageMalleable C2Metasploit ProN-able N-centralRMMRuby on Railsarbitrary file readauthentication bypassexploited in the wildlibvipsmanaged service providersremote code executionremote unauthenticated
What happened
Rapid7 reporting highlights two critical 2026 vulnerabilities: CVE-2026-18577, an N-able N-central authentication bypass exploited in the wild that enables unauthenticated attackers to gain administrative control of RMM servers; and CVE-2026-66066, a critical Ruby on Rails Active Storage/libvips arbitrary file-read vulnerability that can expose secrets and potentially lead to remote code execution. The feed also includes Metasploit Pro 5.1 release information and non-security corporate and event announcements.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- rapid7_blog
- Record identifier
- 1bb5b31201b39c2b6c29800a3689c77b185b78873db5ed1bbf825ac0e875d812
- Enrichment time
- 2026-08-06T07:23:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.