DIRAS TAKE
Urgent: this CVE is listed on CISA’s Known Exploited Vulnerabilities catalog with a federal remediation deadline of 2026-08-07, so prioritize mitigation immediately; public exploit code also exists, increasing immediate risk.
What is CVE-2026-18556?
Remote unauthenticated attackers can bypass authentication on N-able N-central, allowing access to protected functionality and sensitive data; tracked as CVE-2026-18556. The issue affects N-central through 2026.1 (2026.x branch); an attacker only needs network access to the N-central service and no valid credentials or user interaction to exploit the alternate path weakness. The underlying flaw is an authentication bypass (CWE-288) that can lead to confidentiality and integrity impact. The weakness is classified as CWE-288 (Authentication Bypass Using an Alternate Path).
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of N-able N-central are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2026.x | 2026.1 and earlier |
Is CVE-2026-18556 being exploited?
CISA added CVE-2026-18556 to its Known Exploited Vulnerabilities catalog on 2026-08-04, and U.S. federal agencies are required to remediate by 2026-08-07. Public exploit code is available.
How to fix CVE-2026-18556
- Isolate or restrict network exposure of N-central to trusted management networks and VPNs.
- Follow N-able’s mitigation guidance and implement any recommended configuration changes immediately.
- Monitor logs and authentication-related telemetry for suspicious access attempts and indicators of compromise.
- Follow CISA’s KEV remediation instructions, and consider discontinuing use of the product if mitigations are unavailable.
Frequently asked questions
Is CVE-2026-18556 being actively exploited?
CISA added CVE-2026-18556 to its Known Exploited Vulnerabilities catalog on 2026-08-04 and required remediation by 2026-08-07; public exploit code is also available.
Which N-central versions are affected by CVE-2026-18556?
N-able N-central versions through 2026.1 (the 2026.x branch, 2026.1 and earlier) are affected.
Is there a patch for CVE-2026-18556?
No fixed version is listed in the vendor-affected data; apply vendor mitigations and reduce exposure until a vendor patch is released.
Does CVE-2026-18556 require authentication?
No; the vulnerability is an authentication bypass that allows unauthenticated network attackers to access N-central functionality without valid credentials.
References
- nvd.nist.gov/vuln/detail/CVE-2026-18556
- cve.org/CVERecord?id=CVE-2026-18556
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556
- uptime.n-able.com
- All N-able CVEs on CVE Radar
- CVEs published in September 2026