CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2026-18577, is an authentication bypass using an alternate path or channel in N-able N-central.
Intelligence analysis by Llama
CISA has added a new vulnerability to its KEV Catalog due to evidence of active exploitation. The vulnerability affects N-able N-central and allows for authentication bypass using an alternate path or channel.
Imagine you have a password to get into a secure room. But, someone finds a way to get in without using the password. This is like a vulnerability in a computer system that allows someone to get in without being detected. It's like a backdoor that can be used by bad people to do bad things.
Analysis
A New Vulnerability Added to the KEV Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. The vulnerability, CVE-2026-18577, is an authentication bypass using an alternate path or channel in N-able N-central. This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities.
Prioritizing Remediation
CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. While BOD 26-04 applies only to FCEB agencies, CISA believes that all organizations should prioritize the remediation of high-risk vulnerabilities to prevent potential exploitation.
Key points
- CISA has added one new vulnerability to its KEV Catalog, CVE-2026-18577, due to evidence of active exploitation.
- The vulnerability affects N-able N-central and allows for authentication bypass using an alternate path or channel.
- CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities.
- BOD 26-04 establishes vulnerability management requirements for FCEB agencies and requires prioritization of rapid remediation of high-risk vulnerabilities.
If organizations prioritize the remediation of high-risk vulnerabilities, they can reduce the risk of exploitation and protect their systems and data. This can be achieved by adopting risk-based vulnerability management and following the guidelines set out in BOD 26-04.
If organizations do not prioritize the remediation of high-risk vulnerabilities, they may be at risk of exploitation. This can lead to significant risks to the federal enterprise and potentially result in data breaches or system compromise.



