CISA added CVE-2026-18556, an authentication bypass in N-able N-central, to its Known Exploited Vulnerabilities catalog on August 4, 2026, with a federal remediation deadline of August 7, 2026.
What Is It
CVE-2026-18556 is an authentication bypass using an alternate path or channel (CWE-288) in N-able N-central. Per the NVD description, the flaw "allows Authentication Bypass" against affected instances.
NVD assigns a CVSS 3.1 base score of 7.4 (HIGH) with vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N, network-reachable, no privileges, no user interaction, but high attack complexity, with high confidentiality and integrity impact. A secondary CVSS 4.0 score of 8.2 (HIGH) was also published by the CNA. The CVE was published August 1, 2026, and NVD status is Analyzed.
Why It Matters
CISA's KEV listing confirms this vulnerability is under active exploitation. CISA's SSVC decision data reinforces that assessment: exploitation is rated active, the vulnerability is automatable: yes, and technical impact is rated total.
An unauthenticated bypass on a remote monitoring and management platform is high-value by nature; access to the management plane exposes whatever the platform manages. The three-day window between KEV addition (August 4) and the due date (August 7) is unusually tight and signals urgency.
Known ransomware campaign use is listed as Unknown.
What's Vulnerable
- Vendor/Product: N-able N-central
- Affected versions: all versions through 2026.1 (CPE:
cpe:2.3:a:n-able:n-central:*, version end including 2026.1)
Patch Status
CISA's required action is to apply mitigations in accordance with vendor instructions, in compliance with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's "Forensics Triage Requirements." For cloud services, follow applicable BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and adhering to BOD 26-04 patching guidelines. Due date: August 7, 2026.
N-able published a security update blog post dated August 2, 2026, and maintains a status page carrying hotfix/mitigation notices for N-central 2026.3.
Sources
- NVD, CVE-2026-18556: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
- CISA Known Exploited Vulnerabilities Catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18556
- N-able Security Update, August 2, 2026: https://www.n-able.com/blog/n-central-security-update-august-2-2026
- N-able Uptime (Vendor Advisory): https://uptime.n-able.com/
- N-able Status; N-central 2026.3 Hotfix 1: https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/
- CISA BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- CISA BOD 26-04 Implementation Guidance: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk