N-able npm Package Vulnerability CVE-2026-18577 Exploited in the Wild
The N-able npm package vulnerability CVE-2026-18577 has been exploited in the wild. Threat actors found a patch bypass after the initial patch was released.
What happened
The N-able npm package vulnerability, tracked as CVE-2026-18577, has been actively exploited by threat actors. The initial patch released by N-able was found to be incomplete, allowing attackers to bypass authentication and take over N-central servers. N-able has since released a hotfix, version 2026.3 HF1, to address the issue.
CISA has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog due to reports of active exploitation. Successful exploitation can allow remote attackers to gain administrative access to vulnerable N-central servers and deploy persistence mechanisms on managed endpoints.
N-able recommends that all customers upgrade to the latest patched version, 2026.3.1.7, and remove any malicious tunnel services from managed endpoints if evidence of compromise is found. Hosted NCOD instances will be upgraded automatically, while self-hosted servers must be upgraded by the customer.
How 0Day mitigates this
n-able is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.