CVE-2026-18556
HIGH KEVN-able N-central - Unauthenticated Administrative Account Takeover
Title source: ruleExploitation Summary
CVE-2026-18556 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added August 4, 2026. EIP tracks 1 public exploit from researchers including CreamyG31337.
AI-analyzed exploit summary This repository provides a read-only PowerShell-based hunting tool for detecting post-exploitation artifacts related to CVE-2026-18556 and CVE-2026-18577 in N-able N-central. The script checks for indicators of compromise (IoCs) such as rogue Cloudflare Tunnel services, suspicious service paths, and malicious Take Control logs without altering system state.
Description
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Exploits (1)
This repository provides a read-only PowerShell-based hunting tool for detecting post-exploitation artifacts related to CVE-2026-18556 and CVE-2026-18577 in N-able N-central. The script checks for indicators of compromise (IoCs) such as rogue Cloudflare Tunnel services, suspicious service paths, and malicious Take Control logs without altering system state.
References (3)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N