The Patch That Wasn't: CVE-2026-18577 and the Incomplete-Fix Problem
N-able patched an authentication bypass in N-central. Attackers found what the patch missed and used it as a zero-day, pivoting into Microsoft 365 and Okta. Incomplete fixes are their own bug class.