CISA has added CVE‑2026‑18556 to its Known Exploited Vulnerabilities catalogue. The entry concerns N‑able’s N‑central product and covers the N‑able N‑central Authentication Bypass Using an Alternate Path or Channel Vulnerability. This flaw lets an attacker bypass authentication by using an alternate route to gain access to the system.
The vulnerability is an authentication bypass that can be triggered over the network, allowing unauthenticated users to obtain privileged access. It has been assigned a CVSS v3.1 score of 8.2, rating it as HIGH severity. N‑able has released a security update that addresses the issue, and a patch is available through the vendor’s advisory.
Active exploitation of this flaw has been confirmed, which is why it appears in the KEV catalogue. There is no public evidence linking the vulnerability to ransomware campaigns at this time. CISA requires that affected systems be mitigated by 7 August 2026.
Federal Civilian Executive Branch agencies must apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26‑04 Prioritizing Security Updates Based on Risk and CISA’s Forensics Triage Requirements. They should follow the applicable BOD 26‑04 guidance for cloud services or discontinue use of the product if mitigations are unavailable, and they must evaluate each asset’s internet exposure to ensure adherence to BOD 26‑04 patching guidelines. All other organisations are advised to review their exposure to N‑central and apply the vendor’s patch or mitigations as soon as practicable.
For full details, see the NVD entry at https://nvd.nist.gov/vuln/detail/CVE-2026-18556 and the CISA KEV catalogue.