CVE-2026-18556

Published Aug 1, 2026

Last updated 15 hours ago

Exploit knownCVSS high 8.2
N-central
Zero-day
N-able N-central

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18556 describes an authentication bypass vulnerability found in N-able N-central, impacting versions up to and including 2026.1. This flaw, categorized as an "unauthenticated administrative account takeover," stems from an alternate path or channel that allows for authentication bypass (CWE-288). The vulnerability enables an unauthenticated attacker to circumvent existing authentication mechanisms and gain unauthorized administrative access to N-able N-central servers. N-able initially released a fix for this issue in version 2026.2, but a subsequent discovery revealed an incomplete patch, leading to a related vulnerability, CVE-2026-18577, which affected builds prior to 2026.3.1.7.

Description
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Source
a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
NVD status
Analyzed
Products
n-central

Risk scores

CVSS 4.0

Type
Secondary
Base score
8.2
Impact score
-
Exploitability score
-
Vector string
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity
HIGH

CVSS 3.1

Type
Primary
Base score
7.4
Impact score
5.2
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

Known exploits

Data from CISA

Vulnerability name
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Exploit added on
Aug 4, 2026
Exploit action due
Aug 7, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

a5532a13-c4dd-4202-bef1-e0b8f2f8d12b
CWE-288

Social media

Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.

Hype score

16

  1. 🛡️ CYBER BULLETIN | 05/08/2026 Three relevant updates for today: 1. CISA adds three actively exploited flaws to the KEV catalog CISA has listed CVE-2026-9198 (IBM Langflow code injection enabling unauthenticated RCE on default installs), CVE-2026-18556 (N-able N-central ht

    @FrontieraTechIT

    5 Aug 2026

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. An RMM platform got breached this week, and the first patch didn't hold. N-able fixed an N-central auth bypass (CVE-2026-18556) in version 2026.2. This week they found attackers using an alternate path into the same flaw — CVE-2026-18577, hotfixed August 2. https://t.co/phOkvPq

    @Blackicelabs

    5 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. CISA added CVE-2026-9198, CVE-2026-34486 and CVE-2026-18556 to the KEV catalog. CVE-2026-9198 lets unauthenticated attackers chain Langflow APIs for code execution. CVE-2026-34486 bypasses Apache Tomcat EncryptInterceptor encryption. N-central CVE-2026-18556 enables auth bypass;

    @WorldCyberNewsX

    5 Aug 2026

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CISAが既知の悪用された脆弱性3件をカタログに追加 CISA Adds Three Known Exploited Vulnerabilities to Catalog #CISA (Aug 4) CVE-2026-9198 IBM Langflow コードインジェクションの脆弱性 CVE-2026-18556 N-able N-central認証バイパス(代替パ

    @foxbook

    5 Aug 2026

    275 Impressions

    1 Retweet

    2 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CISA KEV: N-able N-central Auth Bypass — CVSS 8.8 CVE-2026-18577: Unauthenticated RMM takeover via incomplete patch for CVE-2026-18556. Apply hotfix NOW. → https://t.co/kaxDK17hCC #cybersecurity #infosec #Nable #CISAKEV #MSP #ThreatIntel

    @ThreatAft

    5 Aug 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が、既知の悪用された脆弱性カタログに、LangflowのCVE-2026-9198、N-able N-centralのCVE-2026-18556、Apache TomcatのCVE-2026-34486を追加。対処期限は3日後の8/7。ランサムウ

    @__kokumoto

    4 Aug 2026

    756 Impressions

    0 Retweets

    3 Likes

    3 Bookmarks

    1 Reply

    0 Quotes

  7. Heads-up: CVE-2026-18577 is under active exploitation. An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions throug… Risk 30/100 · EPSS 1%. This belongs at the top of your patch queue. https://t.co/6nmrcmsgll #CVE

    @BytesNora

    4 Aug 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🛡️We added IBM Langflow vulnerability CVE-2026-9198, N-able N-central vulnerability CVE-2026-18556 & Apache Tomcat vulnerability CVE-2026-34486 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity

    @CISACyber

    4 Aug 2026

    9071 Impressions

    14 Retweets

    38 Likes

    8 Bookmarks

    5 Replies

    1 Quote

  9. @Nable published an N-central security advisory for CVE-2026-18556 and CVE-2026-18577 on Aug 2 with 6 IOC IP addresses. We were already tracking 2 of them two months before disclosure. CVE-2026-18577 was announced after an incomplete patch for CVE-2026-18556 was released. The

    @LupovisDefence

    4 Aug 2026

    183 Impressions

    0 Retweets

    0 Likes

    2 Bookmarks

    0 Replies

    1 Quote

  10. 🐛 VULNERABILITIES CVE Notify: 🚨 [CVE-2026-18556](https://t.co/pOfH31XSsE) Authentication bypass using an alternate path or cha... https://t.co/pOfH31XSsE #CVE #ZeroDay #PatchManagement

    @MalwareObserver

    4 Aug 2026

    35 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. 『an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556』 CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild https://t.co/HeDkaQwj7L

    @autumn_good_35

    4 Aug 2026

    343 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. 🚨 CISA KEV — Patch by these August 2026 deadlines: 🔴 CVE-2026-18577 | N-able N-central | CVSS 8.2 Auth bypass (incomplete fix for CVE-2026-18556) → admin takeover. Actively exploited. 📅 Due Aug 6 🟡 CVE-2025-68686 | Fortinet FortiOS | CVSS 5.9 Bypasses SSL-VPN

    @techepages

    4 Aug 2026

    91 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. N-able has shipped N-central 2026.3 Hotfix 1 to address CVE-2026-18577, an authentication bypass flaw already exploited in the wild. The issue affects versions up to 2026.1 and resulted from an incomplete remediation of CVE-2026-18556. CVSS v4.0 score is 8.2 (High). IoCs have

    @WorldCyberNewsX

    4 Aug 2026

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. cisa just added an n-able n-central flaw to the kev catalog after customers got hit. the kicker: cve-2026-18577 is an incomplete patch for cve-2026-18556. they shipped a fix, declared victory, and the bug just wore a slightly different mask. https://t.co/6vlhgmQIs9

    @kernelrot

    4 Aug 2026

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-18556 / CVE-2026-18577 | Arctic Wolf - https://t.co/IAKHbEY0kA

    @moton

    3 Aug 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2026-18577 has been identified in N-central (CVSS 4.0: 8.2, High), addressing an incomplete remediation of CVE-2026-18556. The vulnerability permits authentication bypass and administrator account takeover without requiring user privileges or interaction. Affected: All

    @techepages

    3 Aug 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2026-18577 An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 https://t.co/LErDuWqWMR

    @CVEnew

    2 Aug 2026

    609 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. NVD - CVE-2026-18556 https://t.co/w7wt3CxLkW

    @samilaiho

    2 Aug 2026

    498 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. It is possible to see elevated activities targeting N-able N-central (CVE-2026-18556) https://t.co/jcl9ENKlNP

    @vuldb

    2 Aug 2026

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations