CVE-2026-18556
N-central vulnerability analysis and mitigation

Overview

CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central, a widely used remote monitoring and management (RMM) platform for managed service providers (MSPs). The flaw allows unauthenticated network attackers to circumvent authentication mechanisms via an alternate path or channel, potentially gaining administrative access to the platform. All N-central versions through 2026.1 are affected. The vulnerability was published on August 1, 2026, and has a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, CISA KEV).

Technical details

The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central's authentication logic can be bypassed by accessing an alternate path or channel that does not enforce the standard authentication controls. The attack vector is network-based, requires no privileges or user interaction, and has high attack complexity — suggesting that exploitation requires specific conditions or knowledge of the alternate path. No user interaction is required, and the vulnerability is exploitable remotely without authentication. Technical write-ups from Rapid7 and Arctic Wolf have analyzed the flaw in the context of its companion vulnerability CVE-2026-18577, noting that the initial patch for CVE-2026-18556 was incomplete and left an alternate bypass path open (Rapid7, Arctic Wolf).

Impact

Successful exploitation allows an unauthenticated attacker to gain administrative access to the N-central RMM console — described by researchers as "god mode" access — enabling them to read sensitive data and modify system configuration. Because N-central is used by MSPs to manage endpoints across multiple client organizations, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints. N-able confirmed that attackers were able to reach managed endpoints via the flaw, and China-linked threat actors (Storm-1175) have been reported deploying StormEncryptor ransomware through this access path (CISA KEV, Arctic Wolf, N-able Blog).

Exploitability

CVE-2026-18556 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026, with a due date of August 7, 2026 for federal agencies to remediate (CISA KEV). The EPSS score is approximately 0.27–0.49%, though real-world exploitation has been confirmed. A defensive IOC triage toolkit (not an exploit) was published on GitHub by CreamyG31337 to help defenders detect post-exploitation artifacts (GitHub IOC Toolkit). China-linked threat group Storm-1175 has been attributed to attacks leveraging this vulnerability to deploy StormEncryptor ransomware. The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable" (Rescana, N-able Blog).

Exploitation steps

  1. Reconnaissance: Identify internet-facing N-central instances using tools like Shodan or Censys, targeting versions through 2026.1. N-central is commonly exposed on standard HTTPS ports.
  2. Identify alternate authentication path: Probe the N-central web interface for endpoints or API paths that bypass the primary authentication mechanism — the vulnerability involves an alternate channel that does not enforce standard login controls (CWE-288).
  3. Send unauthenticated request: Craft an HTTP request targeting the alternate path or channel that bypasses authentication, exploiting the incomplete enforcement of access controls.
  4. Gain administrative access: Upon successful bypass, the attacker obtains administrative-level access to the N-central console without valid credentials, enabling full control of the RMM platform.
  5. Lateral movement to managed endpoints: Use N-central's built-in agent management capabilities to push scripts, commands, or malware (e.g., ransomware) to all managed endpoints across MSP client organizations, achieving broad supply-chain compromise (Arctic Wolf, Rapid7).

Indicators of compromise

  • Network: Unexpected or anomalous HTTP requests to N-central web endpoints from unknown external IP addresses, particularly to authentication-adjacent API paths; outbound connections from the N-central server to unknown infrastructure.
  • Logs: N-central access logs showing successful administrative sessions with no corresponding valid login event; authentication log entries reflecting access via alternate paths or channels; unusual administrative actions (policy changes, agent deployments) in audit logs.
  • File System: Unexpected scripts, executables, or agent packages staged on the N-central server or pushed to managed endpoints; presence of StormEncryptor ransomware artifacts on managed systems.
  • Process: Unusual processes spawned by the N-central service account; RMM agent activity on managed endpoints initiating unexpected commands or downloading payloads.
  • Behavioral: New administrative accounts created in N-central without authorization; bulk deployment of scripts or software to managed endpoints outside of normal change windows (GitHub IOC Toolkit, Arctic Wolf).

Mitigation and workarounds

N-able released a security update addressing CVE-2026-18556 and the related CVE-2026-18577 on August 2, 2026, followed by a second hotfix (Hotfix 2) as attackers continued to exploit an incomplete initial patch. Organizations should update N-central to a version beyond 2026.1 immediately, applying all available hotfixes as described in N-able's security update blog posts (N-able Blog). CISA directed federal agencies to remediate by August 7, 2026, per BOD 26-04 guidance. As interim measures, organizations should restrict internet exposure of N-central, monitor for unauthorized administrative sessions, review audit logs for suspicious activity, and verify the integrity of managed endpoint deployments (CISA KEV).

Community reactions

The vulnerability generated significant attention across the security community given N-central's role as a critical MSP management platform. Researchers at Arctic Wolf, Rapid7, ThreatLocker, Field Effect, and eSentire all published advisories and analyses, with ThreatLocker describing the flaw as granting attackers "god mode" access to the RMM console (Arctic Wolf, Rapid7). The Hacker News, SecurityWeek, BleepingComputer, and GovInfoSecurity covered the story extensively, with GovInfoSecurity characterizing the flaw as a "worst-case scenario" for MSPs. The Water ISAC issued a TLP:CLEAR vulnerability notification, and Canada's CCCS published a security advisory. Community discussion on Reddit and Mastodon highlighted urgency around patching, and the incomplete initial patch drew criticism, with one blog post titled "Three fixes shipped in six days, none of them made the thing safe." China-linked threat actor attribution (Storm-1175/StormEncryptor ransomware) further elevated the severity of community response (SecurityWeek, BleepingComputer).

Additional resources


SourceThis report was generated using AI

Related N-central vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-11367CRITICAL10
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025
CVE-2025-11700HIGH8.4
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025
CVE-2026-18577HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
YesYesAug 02, 2026
CVE-2026-18556HIGH8.2
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
YesYesAug 01, 2026
CVE-2025-9316MEDIUM6.9
  • N-central logoN-central
  • cpe:2.3:a:n-able:n-central
NoYesNov 12, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management