Actively exploited
Listed in CISA’s Known Exploited Vulnerabilities catalog since August 4, 2026.
CVE-2026-18556
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
Added to KEV August 4, 2026
Alert details
- Source feed
- CISA KEV
- CVE ID
- CVE-2026-18556
- CWE
- CWE-288
- Affected products
- N-central · N-able N-central · N-able
What happened
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
What it means for your business
N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18556). N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
CISA due date: August 7, 2026
Sources
Related briefs
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability
N-able N-central is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-18577). N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. This vulnerability is the result of an incomplete patch for CVE-2026-18556. CISA remediation due date: 2026-08-06. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability
Apache Tomcat is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-34486). Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. CISA remediation due date: 2026-08-07. PremierePC tracks KEV alerts for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Ongoing Threats of Swatting and Indicators for Community Members
Ongoing Threats of Swatting and Indicators for Community Members — FBI IC3 industry advisory relevant to cyber risk. PremierePC monitors federal alerts for Upstate SC businesses. Read the source link for full guidance or open a ticket if you want help assessing impact.
Windows NTFS Information Disclosure vulnerability
Windows NTFS Information Disclosure vulnerability (CVE-2026-50341) was added to Microsoft’s security update guidance. Acknowledgement Updated PremierePC tracks MSRC advisories for Upstate SC businesses — patch or open a ticket if you need help verifying exposure.
Need help patching?
PremierePC monitors KEV alerts for managed clients and helps teams prioritize remediation before attackers do.