Critical Remote‑Management Flaw in N‑able N‑central (CVE‑2026‑18577 & CVE‑2026‑18556) Added to CISA KEV Catalog
What It Is – N‑able N‑central, a widely‑used remote monitoring and management (RMM) platform, contains two linked vulnerabilities. CVE‑2026‑18556 (CVSS 8.2) was originally disclosed, and an incomplete patch left a second flaw, CVE‑2026‑18577 (CVSS 8.2), exploitable for remote code execution.
Exploitability – CISA has placed the flaw in its Known Exploited Vulnerabilities (KEV) list after observing active exploitation against at‑least one customer environment. Public PoCs have not been released, but attackers are leveraging the unpatched code path in the wild.
Affected Products – N‑able N‑central versions prior to the latest security update (released 2026‑07‑30). The platform is deployed by Managed Service Providers (MSPs) to manage endpoints for SMB and enterprise customers.
Why It Matters for Compliance & Audit Readiness
- Vendor‑risk controls – SOC 2 Trust Services Criteria require documented due‑diligence on third‑party services; an unpatched RMM tool is a direct control gap.
- Continuous evidence – Ongoing monitoring of third‑party patch status provides audit‑ready evidence that you are actively managing supply‑chain risk.
- Incident‑response readiness – Demonstrating a documented remediation workflow for exploited vendor flaws satisfies the “Risk Mitigation” and “System Operations” criteria of SOC 2.
Recommended Actions
- Verify the exact N‑central version across all managed environments.
- Apply the July 2026 security update that fully patches CVE‑2026‑18556 and CVE‑2026‑18577.
- Update your vendor‑risk inventory to flag N‑able as a critical third‑party and schedule recurring patch‑validation scans.
- Document the remediation steps in your SOC 2 evidence repository (change‑control tickets, patch‑deployment logs).
- Integrate automated alerts from a vulnerability‑management tool into your continuous compliance dashboard.
Source: The Hacker News – CISA Adds Exploited N‑able N‑central Flaw to KEV