Skip to main content

Actively exploited

Listed in CISA’s Known Exploited Vulnerabilities catalog since August 4, 2026.

CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able · N-central

Added to KEV August 4, 2026

Alert details

Source feed
CISA KEV
CVE ID
CVE-2026-18556
CWE
CWE-288
Affected products
N-central · N-able N-central · N-able

What happened

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

What it means for your business

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CISA remediation due date: 2026-08-07. If you need help checking exposure, call (864) 335-9223.

Required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA due date: August 7, 2026

Sources

Related briefs

Actively exploited (KEV)

CVE-2026-86218

N-able N-central Static Code Injection Vulnerability

N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-86218). N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. CISA remediation due date: 2026-09-11. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-88097

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability

Microsoft Edge (Chromium-based) Elevation of Privilege vulnerability (CVE-2026-88097) was added to Microsoft’s security update guidance. <p>Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.</p> If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-0899

Out of bounds memory access in V8 in Microsoft Edge vulnerability

Out of bounds memory access in V8 in Microsoft Edge vulnerability (CVE-2026-0899) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Need help patching?

PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.