<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>N-Able on PhllapsNET</title>
    <link>https://www.phllaps.net/tags/n-able/</link>
    <description>Recent content in N-Able on PhllapsNET</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Tue, 04 Aug 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.phllaps.net/tags/n-able/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability-cve-2026-18556/</link>
      <pubDate>Tue, 04 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability-cve-2026-18556/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 7.4&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;7.4 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-04) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-18556.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;CVE-2026-18556 is an authentication bypass in N-able N-central, achieved by reaching the application through an alternate path or channel that skips the normal authentication check. The CVSS vector indicates this is exploitable over the network without authentication or user interaction, though attack complexity is rated high.&lt;/p&gt;</description>
    </item>
    <item>
      <title>N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability</title>
      <link>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</link>
      <pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://www.phllaps.net/posts/n-able-n-central-authentication-bypass-using-an-alternate-path-or-channel-vulnerability/</guid>
      <description>&lt;div style=&#34;background:#dc2626;color:white;padding:16px 18px;border-radius:14px;font-weight:800;font-size:18px;display:flex;align-items:center;gap:12px;box-shadow:0 10px 24px rgba(0,0,0,0.18);&#34;&gt;&lt;span style=&#34;font-size:24px;&#34;&gt;🚨&lt;/span&gt;&lt;span&gt;SEVERITY: HIGH — CVSS 8.1&lt;/span&gt;&lt;span style=&#34;opacity:0.95;font-weight:700;margin-left:auto;&#34;&gt;Security Advisory&lt;/span&gt;&lt;/div&gt;&#xA;&lt;h2 id=&#34;tldr-&#34;&gt;TL;DR 📌&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.&lt;/li&gt;&#xA;&lt;li&gt;Highest CVSS: &lt;strong&gt;8.1 (High)&lt;/strong&gt;.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Listed in CISA KEV&lt;/strong&gt; (2026-08-03) — this is being exploited in the wild.&lt;/li&gt;&#xA;&lt;li&gt;&lt;strong&gt;Check the advisory for fixed releases&lt;/strong&gt; — remediation detail is in the vendor link below.&lt;/li&gt;&#xA;&lt;li&gt;CVEs: CVE-2026-18577.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h2 id=&#34;what-it-is&#34;&gt;What it is&lt;/h2&gt;&#xA;&lt;p&gt;N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
