CVE-2026-18556
N-central Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central, a widely used remote monitoring and management (RMM) platform for managed service providers (MSPs). The flaw allows unauthenticated network attackers to circumvent authentication mechanisms via an alternate path or channel, potentially gaining administrative access to the platform. All N-central versions through 2026.1 are affected. The vulnerability was published on August 1, 2026, and has a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, CISA KEV).

Dettagli tecnici

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central's authentication logic can be bypassed by accessing an alternate path or channel that does not enforce the standard authentication controls. The attack vector is network-based, requires no privileges or user interaction, and has high attack complexity — suggesting that exploitation requires specific conditions or knowledge of the alternate path. No user interaction is required, and the vulnerability is exploitable remotely without authentication. Technical write-ups from Rapid7 and Arctic Wolf have analyzed the flaw in the context of its companion vulnerability CVE-2026-18577, noting that the initial patch for CVE-2026-18556 was incomplete and left an alternate bypass path open (Rapid7, Arctic Wolf).

Impatto

Successful exploitation allows an unauthenticated attacker to gain administrative access to the N-central RMM console — described by researchers as "god mode" access — enabling them to read sensitive data and modify system configuration. Because N-central is used by MSPs to manage endpoints across multiple client organizations, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints. N-able confirmed that attackers were able to reach managed endpoints via the flaw, and China-linked threat actors (Storm-1175) have been reported deploying StormEncryptor ransomware through this access path (CISA KEV, Arctic Wolf, N-able Blog).

Sfruttabilità

CVE-2026-18556 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026, with a due date of August 7, 2026 for federal agencies to remediate (CISA KEV). The EPSS score is approximately 0.27–0.49%, though real-world exploitation has been confirmed. A defensive IOC triage toolkit (not an exploit) was published on GitHub by CreamyG31337 to help defenders detect post-exploitation artifacts (GitHub IOC Toolkit). China-linked threat group Storm-1175 has been attributed to attacks leveraging this vulnerability to deploy StormEncryptor ransomware. The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable" (Rescana, N-able Blog).

Passaggi di sfruttamento

  1. Reconnaissance: Identify internet-facing N-central instances using tools like Shodan or Censys, targeting versions through 2026.1. N-central is commonly exposed on standard HTTPS ports.
  2. Identify alternate authentication path: Probe the N-central web interface for endpoints or API paths that bypass the primary authentication mechanism — the vulnerability involves an alternate channel that does not enforce standard login controls (CWE-288).
  3. Send unauthenticated request: Craft an HTTP request targeting the alternate path or channel that bypasses authentication, exploiting the incomplete enforcement of access controls.
  4. Gain administrative access: Upon successful bypass, the attacker obtains administrative-level access to the N-central console without valid credentials, enabling full control of the RMM platform.
  5. Lateral movement to managed endpoints: Use N-central's built-in agent management capabilities to push scripts, commands, or malware (e.g., ransomware) to all managed endpoints across MSP client organizations, achieving broad supply-chain compromise (Arctic Wolf, Rapid7).

Indicatori di compromesso

  • Network: Unexpected or anomalous HTTP requests to N-central web endpoints from unknown external IP addresses, particularly to authentication-adjacent API paths; outbound connections from the N-central server to unknown infrastructure.
  • Logs: N-central access logs showing successful administrative sessions with no corresponding valid login event; authentication log entries reflecting access via alternate paths or channels; unusual administrative actions (policy changes, agent deployments) in audit logs.
  • File System: Unexpected scripts, executables, or agent packages staged on the N-central server or pushed to managed endpoints; presence of StormEncryptor ransomware artifacts on managed systems.
  • Process: Unusual processes spawned by the N-central service account; RMM agent activity on managed endpoints initiating unexpected commands or downloading payloads.
  • Behavioral: New administrative accounts created in N-central without authorization; bulk deployment of scripts or software to managed endpoints outside of normal change windows (GitHub IOC Toolkit, Arctic Wolf).

Mitigazione e soluzioni alternative

N-able released a security update addressing CVE-2026-18556 and the related CVE-2026-18577 on August 2, 2026, followed by a second hotfix (Hotfix 2) as attackers continued to exploit an incomplete initial patch. Organizations should update N-central to a version beyond 2026.1 immediately, applying all available hotfixes as described in N-able's security update blog posts (N-able Blog). CISA directed federal agencies to remediate by August 7, 2026, per BOD 26-04 guidance. As interim measures, organizations should restrict internet exposure of N-central, monitor for unauthorized administrative sessions, review audit logs for suspicious activity, and verify the integrity of managed endpoint deployments (CISA KEV).

Reazioni della comunità

The vulnerability generated significant attention across the security community given N-central's role as a critical MSP management platform. Researchers at Arctic Wolf, Rapid7, ThreatLocker, Field Effect, and eSentire all published advisories and analyses, with ThreatLocker describing the flaw as granting attackers "god mode" access to the RMM console (Arctic Wolf, Rapid7). The Hacker News, SecurityWeek, BleepingComputer, and GovInfoSecurity covered the story extensively, with GovInfoSecurity characterizing the flaw as a "worst-case scenario" for MSPs. The Water ISAC issued a TLP:CLEAR vulnerability notification, and Canada's CCCS published a security advisory. Community discussion on Reddit and Mastodon highlighted urgency around patching, and the incomplete initial patch drew criticism, with one blog post titled "Three fixes shipped in six days, none of them made the thing safe." China-linked threat actor attribution (Storm-1175/StormEncryptor ransomware) further elevated the severity of community response (SecurityWeek, BleepingComputer).

Risorse aggiuntive


FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato N-central Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-86218CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Sep 06, 2026
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
Aug 01, 2026
CVE-2026-86207HIGH7.7
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoSep 05, 2026
CVE-2026-86206MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoSep 05, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità