🚨SEVERITY: HIGH — CVSS 7.4Security Advisory
TL;DR 📌
- N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
- Highest CVSS: 7.4 (High).
- Listed in CISA KEV (2026-08-04) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2026-18556.
What it is
CVE-2026-18556 is an authentication bypass in N-able N-central, achieved by reaching the application through an alternate path or channel that skips the normal authentication check. The CVSS vector indicates this is exploitable over the network without authentication or user interaction, though attack complexity is rated high.