CVE-2026-18556

High PUBLISHED

Unauthenticated administrative account takeover

Vendor: N-able Product: N-central

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.2 High

At a Glance

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

CVE Published
Aug 01, 2026
Exploitation Reported
Aug 01, 2026
CVSS
8.2 High
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
N-able
N-central

0 to <= 2026.1

Affected

CVE References