HIGH 8.2 NVD ACTIVELY EXPLOITED
CVE-2026-18556
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
Affected Products
- n-able/n-central
References
This high severity vulnerability with a CVSS score of 8.2 was published on 2026-08-01 via NVD. ⚠ This vulnerability is in the CISA Known Exploited Vulnerabilities (KEV) catalog — it is being actively exploited in the wild. Affected: n-able/n-central.
Risk Timeline
CVE Disclosed2026-08-01 · 2 days ago
CISA KEV — Actively ExploitedU.S. federal agencies required to patch · confirmed threat-actor activity
Remediation Resources
Official Advisory
www.n-able.com/blog/n-central-security-update-august-2-2026Analysis & PoC
uptime.n-able.com/Related Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-18577 KEV | An incomplete patch for CVE-2026-18556 allows for authentication bypass and acco | HIGH | 8.2 |
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.