LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

RBRecent Breaches Vulnerability Intelligence·Aug 4, 2026
CVSS 8.2 · High⚠ Actively exploited (CISA KEV)
8.2
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Aug 7, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2026-18556 to its Known Exploited Vulnerabilities catalog on Aug 4, 2026, with a federal patch deadline of Aug 7, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVE-2026-18556 is an authentication bypass vulnerability in N-able N-central. It stems from an alternate path or channel that can let an attacker skip normal login controls. For IT and security teams running this remote monitoring and management platform, the issue matters because successful bypass can open management functions that should require valid credentials. Confirm exact impact, fixed builds, and deployment guidance against the vendor advisory.

CISA describes the flaw as an authentication bypass using an alternate path or channel. Ransomware use is not documented in the provided facts. Treat internet-facing or broadly reachable instances as higher priority until you verify patch status and exposure.

How it works

The weakness is classed as CWE-288: Authentication Bypass Using an Alternate Path or Channel. In this class of flaw, the product enforces authentication on the primary login path but leaves another route, interface, or channel that does not apply the same checks. An attacker who can reach that alternate path may obtain an authenticated session or equivalent access without supplying valid credentials through the intended flow.

Public detail in the given record does not describe the precise endpoint, protocol, or request sequence. Do not assume a specific exploit chain. In general, abuse of this class involves discovering and calling the unprotected path, then using the resulting access to perform actions reserved for authenticated users. Confirm mechanics and any proof-of-concept boundaries only from the vendor advisory and your own controlled testing.

Am I affected? How to find it in your systems

N-able N-central is typically deployed by managed service providers and internal IT teams as a central console for device management, remote access, and related operations. It may run on-premises, in customer-controlled infrastructure, or in hosted arrangements depending on how your organization licensed and installed it.

Inventory steps:

Telemetry and log signs of exploitation are not detailed in the provided facts. In general for authentication-bypass issues, look for successful session establishment without corresponding normal login events, access to privileged API or UI functions from unexpected sources, anomalous authentication-related errors followed by authorized activity, and new or unusual administrative actions. Baseline normal console behavior first so anomalies stand out. Confirm any vendor-specific indicators against the advisory.

How to remediate

Patch first. Apply the vendor update or mitigation package specified for CVE-2026-18556 in the N-able advisory. Follow CISA’s direction to apply mitigations in accordance with vendor instructions, align with BOD 26-04 prioritization based on risk, and meet applicable forensics triage expectations. For cloud-delivered or vendor-hosted components, follow BOD 26-04 cloud guidance; if mitigations are unavailable, discontinue use as directed by that guidance.

After patching:

If you can't patch immediately

Reduce attack surface until the vendor fix is installed:

Compensating controls do not replace the patch. Schedule the official update as soon as operationally feasible and reassess exposure afterward.

If your data may have been exposed

Actively exploited authentication bypasses on management platforms can lead to unauthorized access, configuration tampering, or lateral movement into managed endpoints. The facts for this CVE do not document ransomware use; still, treat confirmed or suspected compromise as an incident: isolate affected consoles, preserve logs, rotate secrets, and follow your forensics process in line with CISA triage expectations. Stakeholders should evaluate each asset’s internet exposure and patching status under BOD 26-04. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior public breach sets while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedN-able · N-central
WeaknessCWE-288
CVSS base score8.2 (High)
CVSS vectorCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedAug 1, 2026
Added to CISA KEVAug 4, 2026
Federal patch deadlineAug 7, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities