N-able N-central Authentication Bypass Vulnerabilities
CVE-2026-18556 and CVE-2026-18577 are authentication bypass vulnerabilities affecting N-able N-central, a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams to administer large fleets of endpoints. CVE-2026-18577 exists because the original remediation for CVE-2026-18556 did not fully resolve the underlying authentication logic issue, leaving a residual authentication bypass that attackers could still exploit. Successful exploitation allows an unauthenticated attacker to gain administrative access to the N-central server, which can then be used to compromise managed endpoints. CVE-2026-18556 carries a CVSS v3.1 score of 7.4, while CVE-2026-18577 is rated 8.1. Both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. Horizon3.ai’s research team reverse engineered these vulnerabilities and developed Rapid Response tests for NodeZero®.
Technical Details
CVE-2026-18556 is an authentication bypass caused by improper enforcement of authentication controls through an alternate access path. It affects N-central versions through 2026.1.
The initial vendor remediation did not completely eliminate the underlying authentication flaw. As a result, CVE-2026-18577 was assigned to the remaining authentication bypass affecting N-central versions prior to 2026.3 Hotfix 1 (build 2026.3.1.7).
An attacker can remotely authenticate without valid credentials and obtain administrative access to the N-central server. Because N-central manages customer infrastructure and endpoints, a successful compromise allows attackers to leverage built-in administrative capabilities, including remote management functions such as Take Control, to access downstream systems.
Both vulnerabilities have been observed in active exploitation and should be treated as high priority for remediation.
NodeZero® Proactive Security Platform — Rapid Response
A NodeZero Rapid Response test has been developed to safely validate whether this authentication bypass can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
- Run the Rapid Response test: Launch from the NodeZero platform to determine whether unauthenticated administrative access is possible.
- Patch immediately: Upgrade to N-central 2026.3 Hotfix 1 (build 2026.3.1.7) or a later vendor-supported release.
- Re-run the test: Confirm the authentication bypass is no longer exploitable after remediation.
Affected versions & patch
Affected
CVE-2026-18556
- N-central versions through 2026.1.
CVE-2026-18577
- N-central versions prior to 2026.3 Hotfix 1 (build 2026.3.1.7).
Patch
Upgrade to N-central 2026.3 Hotfix 1 (build 2026.3.1.7) or any later vendor-supported release.
Mitigations
If immediate patching is not possible, N-able recommends:
- Restrict access to the N-central management interface to trusted IP addresses.
- Remove unnecessary internet exposure.
- Monitor authentication logs for unauthorized administrative access.
- Review Take Control activity and other privileged management operations for suspicious behavior.
These measures reduce exposure but do not eliminate the vulnerability. Applying the vendor hotfix remains the recommended remediation.
Timeline
- August 1, 2026: N-able published its initial security advisory for CVE-2026-18556 and warned customers of active exploitation.
- August 2, 2026: N-able released N-central 2026.3 Hotfix 1 (build 2026.3.1.7) to address the incomplete remediation.
- August 3, 2026: CISA added the N-able N-central authentication bypass vulnerabilities to the Known Exploited Vulnerabilities (KEV) Catalog.
- August 4, 2026: N-able updated its advisory to identify CVE-2026-18577 as the residual authentication bypass and confirmed attackers had used the vulnerability to obtain administrative access to N-central servers.
- August 5, 2026: Horizon3.ai released NodeZero Rapid Response tests for CVE-2026-18556 and CVE-2026-18577.
References
- N-able Security Update – August 4, 2026
- N-central 2026.3 Hotfix 1 Mitigation for CVE-2026-18577
- N-central 2026.3 HF1 Release Notes
- CVE.org Record – CVE-2026-18556
- CVE.org Record – CVE-2026-18577
- NIST NVD – CVE-2026-18556
- NIST NVD – CVE-2026-18577
- CISA Known Exploited Vulnerabilities Catalog
- ITPro Coverage – MSPs Urged to Patch Immediately After N-able Issues Hotfix for N-central ‘God Mode’ Flaw
