CVE-2026-18556

HIGH KEV

N-able N-central - Unauthenticated Administrative Account Takeover

Title source: rule
STIX 2.1

Exploitation Summary

CVE-2026-18556 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 4, 2026. EIP tracks 1 public exploit from researchers including CreamyG31337.

AI-analyzed exploit summary This repository provides a read-only PowerShell-based hunting tool for detecting post-exploitation artifacts related to CVE-2026-18556 and CVE-2026-18577 in N-able N-central. The script checks for indicators of compromise (IoCs) such as rogue Cloudflare Tunnel services, suspicious service paths, and malicious Take Control logs without altering system state.

Description

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.

Exploits (1)

github SCANNER
by CreamyG31337 · powershellpoc
https://github.com/CreamyG31337/ncentral-compromise-ioc-triage

This repository provides a read-only PowerShell-based hunting tool for detecting post-exploitation artifacts related to CVE-2026-18556 and CVE-2026-18577 in N-able N-central. The script checks for indicators of compromise (IoCs) such as rogue Cloudflare Tunnel services, suspicious service paths, and malicious Take Control logs without altering system state.

Classification
Scanner 99%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: N-able N-central (vulnerable versions prior to 2026.3.1.7)
No auth needed
Prerequisites: Access to a Windows endpoint managed by N-able N-central · Administrative privileges to run the script
mistral-large-3 · analyzed Aug 06, 2026 Full analysis →

Scores

CVSS v3 7.4
EPSS 0.0049
EPSS Percentile 39.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-08-04
VulnCheck KEV 2026-08-01
ENISA EUVD EUVD-2026-51918
CWE
CWE-288
Status published
Products (2)
N-able/N-central < 2026.1
n-able/n-central < 2026.1
Published Aug 01, 2026
KEV Added Aug 04, 2026
Tracked Since Aug 02, 2026