CVE-2026-18556 is a high-severity authentication bypass in N-able N-central (up to v2026.1) that is actively exploited in the wild.
| Product | Version Start | Version End (excl.) | Status |
|---|---|---|---|
| n-central | * | 2026.1 | vulnerable |
Immediately install the latest security updates provided by N-able, specifically N-central 2026.3 Hotfix 1 or the most recent stable release that addresses the alternate path authentication bypass.
Identify all N-central instances within your environment running version 2026.1 or earlier and upgrade them to a patched version to eliminate the vulnerability.
Implement strict network access control lists (ACLs) to limit access to the N-central administrative interface to known, trusted IP addresses or require access via a secure VPN.
Conduct a forensic review of authentication logs for any successful logins originating from unusual geographic locations or sessions that appear to bypass standard multi-factor authentication (MFA) workflows.
"Monitor N-central web server logs for requests to unusual or undocumented URL paths that may bypass standard login prompts. Look for successful authentication events that do not correlate with known user activity or MFA challenges. Additionally, inspect network traffic for unauthorized administrative traffic originating from external IP addresses and review audit logs for the creation of unauthorized administrative accounts or unexpected configuration changes."
Experience superior visibility and a simpler approach to cyber risk management