๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Summary
N-able N-central has a vulnerability that allows attackers to bypass authentication (the process of verifying a user's identity) by using an alternate path or channel, giving them unauthorized access to the system. This flaw is currently being exploited by attackers in real-world attacks. Organizations using this product must apply vendor-provided mitigations by August 7, 2026, or stop using the product if no fixes are available.
Solution / Mitigation
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA's BOD 26-04 Prioritizing Security Updates Based on Risk guidance. Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. See N-able's status page at https://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/ for specific mitigation details.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
August 3, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18556
First tracked: August 4, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%