CISA KEV: N-able N-central Authentication Bypass (CVE-2026-18556) Actively Exploited
CISA has added CVE-2026-18556, an authentication bypass using an alternate path or channel in N-able N-central, to its Known Exploited Vulnerabilities (KEV) catalog as of 2026-08-04. Per the advisory, the flaw allows an attacker to bypass authentication controls in N-central through an alternate path or channel. CISA's KEV listing indicates the vulnerability is being actively exploited in the wild, though details on the specific exploitation technique, threat actors involved, or scope of impact have not been disclosed. A CVSS score was not provided in the source data. Whether the vulnerability has been used in ransomware campaigns is currently unknown.
Why It Matters
N-central is a widely used remote monitoring and management (RMM) platform for managed service providers (MSPs), giving it privileged, centralized access to the endpoints and networks of many downstream customers. An authentication bypass in this class of software is high-impact: successful exploitation could let an attacker skip login controls entirely and reach administrative functionality, potentially enabling lateral movement into every organization managed through that N-central instance. Because KEV entries require active exploitation to be confirmed by CISA, this is not a theoretical risk — organizations running N-central, and especially MSPs and their downstream clients, should treat this as an urgent priority.
What Defenders Should Do Now
- Identify all N-central instances in your environment or your MSP's environment and confirm whether they are exposed to the internet.
- Apply vendor-provided patches or mitigations for CVE-2026-18556 as soon as they are available; consult the N-able advisory directly for remediation guidance and affected version ranges.
- Review authentication and access logs on N-central servers for anomalous logins, especially any that bypass expected MFA or SSO flows, or access via unusual paths/endpoints.
- Restrict network exposure of N-central management interfaces where possible (e.g., VPN-only access, IP allow-listing) until patched.
- Monitor for downstream signs of compromise (new admin accounts, unexpected agent/script deployment, credential dumping) on endpoints managed via N-central, given its privileged reach.
- MSP customers should ask their provider directly whether they run N-central and what remediation steps have been taken.
This is a fast-developing item based on CISA's KEV addition, and further technical details from N-able or CISA may refine this picture. For the latest vendor guidance, see the N-able status/advisory page.