CVE-2026-18556
published 2026-08-02CVE-2026-18556: An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
PriorityP192high7.4CVSS 3.1
AVNACHPRNUINSUCHIHAN
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-08-07
Exploited in the wild
EPSS
40.16%
98.6th percentile
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| n-able | n-central | < 2026.3 | 2026.3 |
| n-able | n-central | <= 2026.1 | — |
| n-able | n-central | — | — |
CVSS provenance
nvdv3.17.4HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv4.08.2HIGHCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vulncheck8.2HIGH
cisa8.2HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
cisa·2026-08-04·CVSS 7.4
CVE-2026-18556 [HIGH] CWE-288 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Vulnerability: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Affected: N-able N-central
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Notes: https://uptime.n-able.com/ ;
CISA
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
cisa·2026-08-03·CVSS 8.2
CVE-2026-18577 [HIGH] CWE-288 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Vulnerability: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Affected: N-able N-central
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's interne
GHSA
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
ghsa_unreviewed·2026-08-03·CVSS 8.2
CVE-2026-18577 [HIGH] CWE-288 An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
VulDB
N-able N-central up to 2026.1 improper authentication (EUVD-2026-51918)
vuldb·2026-08-01·CVSS 8.2
CVE-2026-18556 [HIGH] N-able N-central up to 2026.1 improper authentication (EUVD-2026-51918)
A vulnerability has been found in N-able N-central up to 2026.1 and classified as very critical. This vulnerability affects unknown code. Performing a manipulation results in improper authentication.
This vulnerability is identified as CVE-2026-18556. The attack can be initiated remotely. There is not any exploit available.
GHSA
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
ghsa_unreviewed·2026-08-01
CVE-2026-18556 [HIGH] CWE-288 Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
VulnCheck
N-able N-Central Authentication Bypass Using an Alternate Path or Channel
vulncheck·2026·CVSS 8.2
CVE-2026-18556 [HIGH] N-able N-Central Authentication Bypass Using an Alternate Path or Channel
N-able N-Central Authentication Bypass Using an Alternate Path or Channel
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
Affected: N-able N-Central
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://kevintel.com/CVE-2026-18556; https://uptime.n-able.com/event/201454/
VulnCheck
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
vulncheck·2026·CVSS 8.2
CVE-2026-18577 [HIGH] CWE-288 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556.
Affected: N-able N-central
Required Action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and
No detection rules found.
No public exploits indexed.
Hackernews
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
blogs_hackernews·2026-08-10·CVSS 9.8
CVE-2026-18577 [CRITICAL] China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175 , a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor .
The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelligence Team said.
"StormEncryptor is written in C++ and appends the file name extension .encrypted to files it encrypts," Microsoft noted in a series of posts on Bluesky. "It then drops a ransom note named !!!README_FIRST!!!.txt to every scanned
Hackernews
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
blogs_hackernews·2026-08-10
CVE-2026-34348 ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default.
That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place.
That’s only part of it. Here’s everything else that made the Monday recap.
## ⚡ Threat of the Week
Anthropic's Model Attempts to Poison Open-Source Project — A new evaluati
Hackernews
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
blogs_hackernews·2026-08-08·CVSS 7.4
CVE-2026-18577 [HIGH] N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product.
"We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques," the company said.
"This is not a duplicate of our previous communication. Hotfix 2 is required, even if you already applied the earlier hotfix. Hotfix 2 supersedes Hotfix 1 with additional hardening measures t
Hackernews
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
blogs_hackernews·2026-08-05·CVSS 7.4
CVE-2026-9198 [HIGH] CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities ( KEV ) catalog, citing evidence of active exploitation in the wild.
The list of vulnerabilities is as follows -
CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1)
CVE-2026-34486 (CVS score: 7.5) - A missing encryption of sensitive data
Hackernews
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
blogs_hackernews·2026-08-04·CVSS 7.4
CVE-2026-18577 [HIGH] CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities ( KEV ) catalog following reports of active exploitation in the wild.
The vulnerability, tracked as CVE-2026-18577 (CVSS score: 8.2), is a case of incomplete patching for CVE-2026-18556 (CVSS score: 8.2) that allows authentication bypass and account takeover in susceptible versions of the software. The issue has been addressed in version 2026.3 HF1.
"N-able N-central contains
Rapid7
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
blogs_rapid7·2026-08-04·CVSS 7.4
CVE-2026-18577 [HIGH] CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
## Overview
On August 2, 2026, N-able published a security advisory for CVE-2026-18577 , an authentication bypass vulnerability affecting N-central that was discovered being exploited in-the-wild after an incomplete fix for an earlier authentication bypass issue, CVE-2026-18556 was disclosed. CVE-2026-18577 allows a remote unauthenticated attacker to bypass authentication and obtain administrative control of vulnerable N-central servers in affected deployments.
N-able N-central is a widely deployed Remote Monitoring and Management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams to centrally administer servers, workstations, network devices, and other managed assets. Because the platform operates with extensive administrative privileges across customer envi
Hackernews
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
blogs_hackernews·2026-08-03·CVSS 8.2
CVE-2026-18577 [HIGH] N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.
N-central is the remote monitoring and management platform managed service providers and IT teams use to administer customer endpoints.
After compromising an N-central server, the attackers used Take Control
Huntress
Critical N-able N-central Vulnerability and Active Exploitation
blogs_huntress·2026-08-03
CVE-2026-18556 Critical N-able N-central Vulnerability and Active Exploitation
Acknowledgments : Special thanks to Aaron Deal, Chris Bisnett, Aaron Bennett, Sharon Martin, Dave Kleinatland, James Northey, Josh Kiriakoff, Kamal Bennoune, and Michael Tigges for their contributions to this investigation and write-up.
Update: 8/6/26 @ 5:40 PM ET
N-able has released a second hotfix for N-central that supersedes its original hotfix to provide additional hardening measures. Hotfix 2 (2026.3.1.10) is required for organizations running N-central on-premises even if they've applied Hotfix 1 (2026.3.1.7). Organizations are advised to upgrade immediately, following N-able's upgrade instructions . N-able says organizations using hosted N-central (NCOD) do not need to take action, as mitigations have already been applied.
N-able has also published an additional security update
Hackernews
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
blogs_hackernews·2026-08-03
CVE-2026-42897 ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.
Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets.
The full weekly recap report follows.
## ⚡ Threat of the Week
Anthropic Disclosed its Models Targeted 3 O
Bugzilla
CVE-2024-33655 unbound: DNSBomb vulnerability
bugzilla·2024-05-10·CVSS 7.5
CVE-2024-33655 [HIGH] CVE-2024-33655 unbound: DNSBomb vulnerability
CVE-2024-33655 unbound: DNSBomb vulnerability
The DNSBomb attack, via specially timed DNS queries and answers, can cause a Denial of Service on resolvers and spoofed targets.
Unbound itself is not vulnerable for DoS, rather it can be used to take part in a pulsing DoS amplification attack.
Discussion:
Created unbound tracking bugs for this issue:
Affects: fedora-all [bug 2279944]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:18556 https://access.redhat.com/errata/RHSA-2026:18556
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2026:18931 https://access.redhat.com/errata/RHSA-2026:18931
https://documentation.n-able.com/N-central/Release_Notes/GA/Content/N-central_2026.3_HF1_Release_Notes.htmhttps://status.n-able.com/2026/08/02/n-central-2026-3-hotfix-1-mitigation-for-cve-2026-18577/https://www.cve.org/CVERecord?id=CVE-2026-18556https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-18577https://www.n-able.com/blog/n-central-security-update-august-2-2026
2026-08-02
Published
2026-08-04
Added to CISA KEV
Exploited in the wild