CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities Catalog on Aug. 3, citing evidence that the N-able N-central authentication-bypass vulnerability is being actively exploited. The agency classified the flaw as an “Authentication Bypass Using an Alternate Path or Channel” vulnerability.

CISA said vulnerabilities in this category are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. The available notice does not provide exploitation details, affected versions, or a specific remediation measure.

Binding Operational Directive 26-04 requires Federal Civilian Executive Branch agencies to prioritize rapid remediation of catalog-listed CVEs on publicly exposed assets when exploitation would grant total control of the asset. The directive also sets basic expectations for agencies to check whether threat actors compromised a system before a patch was applied.

The directive applies only to FCEB agencies, while CISA encourages other organizations to prioritize vulnerabilities in the KEV Catalog as part of risk-based vulnerability management. CISA said it will continue adding vulnerabilities that meet its criteria. Organizations identifying an exploited vulnerability absent from the catalog can submit it for consideration if it has a CVE identifier, evidence of exploitation, and clear mitigation guidance.