CVE-2026-18556
Unauthenticated administrative account takeover
Description
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
In plain language
AI Act nowCVE-2026-18556 is a way to bypass login and take over an admin account in N-able N-central; because it’s been exploited in the real world and is listed by CISA, a typical small business should treat it as urgent and patch or disable the system if you use it.
CVE-2026-18556 is an unauthenticated administrative account takeover in N-able N-central caused by an authentication-bypass weakness (CWE-288) that lets attackers impersonate an administrator over the network without prior credentials; CISA KEV confirms active real-world exploitation.
What to do now
- Check whether your business uses N-able N-central and whether it’s reachable from the internet (or from any untrusted network).
- Confirm with your IT/vendor whether your N-central version is within the affected range (through 2026.1) and whether it has already been updated with the August 2, 2026 security fix.
- Apply N-able’s remediation guidance and install the security update referenced by N-able’s August 2, 2026 advisory.
- If mitigations/patching can’t be applied quickly, discontinue use of the product or restrict it so it’s not reachable from untrusted networks, per CISA guidance.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
References
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flawen·The Hacker News· Exploited N-central rce
- N-able выпустила уже два патча для уязвимости обхода аутентификации в N-centralru-ru·Хакер (xakep.ru)· Exploited N-central auth-bypass
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawen·The Hacker News· Exploited StormEncryptor Storm-1175
- ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoorsen·The Hacker News· Exploited Mythos 5 UNC6671
- N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577en-us·Help Net Security·
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persisten·The Hacker News· Exploited N-able N-central privilege-escalation
- CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilitiesen-us·SecurityWeek· Exploited Langflow web-app
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploiteden·The Hacker News· Exploited Langflow knaithe
- CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wilden·Rapid7 Blog· Exploited N-central rce
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesen·The Hacker News· Exploited N-able N-central supply-chain
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-18556 and every CVE in our database. Create a free account — no credit card required.
Create Free Account