CVE-2026-18577 is a high-severity authentication bypass vulnerability in N-able N-central, allowing remote attackers to gain administrative access and take over accounts. It results from incomplete patching of CVE-2026-18556 and is actively exploited in the wild, leading to its addition to CISA's KEV catalog.