Fixing and finding
Jump to remediation plan
CVE ID

CVE-2026-18556

Published 2026-08-01
Updated last month
Vendor/s
N-able
Product/s
N-central
Version/s
* > 2026.1
KEV Status
Active Exploitation
Listed in CISA's Known Exploited Vulnerabilities catalog. Active exploitation observed in the wild.
CVSS Score (v3.1)
7.4
/ 10
High
Severity Details
Base score
7.4 High
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Description

CVE-2026-18556 is a high-severity authentication bypass in N-able N-central (up to v2026.1) that is actively exploited in the wild.

CPE

N-able logo
N-able
Product Version Start Version End (excl.) Status
n-central * 2026.1 vulnerable

Related weakness (CWE)

CWE-288

Remediation plan

1

Apply official patches

Immediately install the latest security updates provided by N-able, specifically N-central 2026.3 Hotfix 1 or the most recent stable release that addresses the alternate path authentication bypass.

2

Update affected systems

Identify all N-central instances within your environment running version 2026.1 or earlier and upgrade them to a patched version to eliminate the vulnerability.

3

Restrict access

Implement strict network access control lists (ACLs) to limit access to the N-central administrative interface to known, trusted IP addresses or require access via a secure VPN.

4

Monitor for exploitation

Conduct a forensic review of authentication logs for any successful logins originating from unusual geographic locations or sessions that appear to bypass standard multi-factor authentication (MFA) workflows.

Detection Guidance

"Monitor N-central web server logs for requests to unusual or undocumented URL paths that may bypass standard login prompts. Look for successful authentication events that do not correlate with known user activity or MFA challenges. Additionally, inspect network traffic for unauthorized administrative traffic originating from external IP addresses and review audit logs for the creation of unauthorized administrative accounts or unexpected configuration changes."

References

Sources

NIST National Vulnerability Database (NVD)
CISA Known Exploited Vulnerabilities (KEV)

Experience superior visibility and a simpler approach to cyber risk management