Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.
This issue affects N-central: through 2026.1.
Is CVE-2026-18556 exploited?
Listed in the CISA KEV catalog on 2026-08-04.
Federal remediation due 2026-08-07.
Past that date by 8 days.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2026-18556
PlainSec has not published a story about this CVE.