CVE-2026-18556
HIGH KEVN-able N-central - Unauthenticated Administrative Account Takeover
Title source: ruleExploitation Summary
CVE-2026-18556 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 4, 2026.
Description
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
References (2)
Core 2
Core References
Scores
CVSS v3
7.4
EPSS
0.0027
EPSS Percentile
19.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CISA KEV
2026-08-04
VulnCheck KEV
2026-08-01
ENISA EUVD
EUVD-2026-51918
CWE
CWE-288
Status
published
Products (2)
N-able/N-central
< 2026.1
n-able/n-central
< 2026.1
Published
Aug 01, 2026
KEV Added
Aug 04, 2026
Tracked Since
Aug 02, 2026