N-central CVE-2026-18577: 28.6% unpatched, and patching alone won't evict
N-able's N-central hotfix closes an authentication bypass that was exploited as a zero-day from 31 July 2026. It does not remove the tunnel service the attacker registered on your managed endpoints. Here is the order