
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18556 is an authentication bypass vulnerability (CWE-288) in N-able N-central, a widely used remote monitoring and management (RMM) platform for managed service providers (MSPs). The flaw allows unauthenticated network attackers to circumvent authentication mechanisms via an alternate path or channel, potentially gaining administrative access to the platform. All N-central versions through 2026.1 are affected. The vulnerability was published on August 1, 2026, and has a CVSS v3.1 base score of 7.4 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, CISA KEV).
The vulnerability is classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel), meaning N-central's authentication logic can be bypassed by accessing an alternate path or channel that does not enforce the standard authentication controls. The attack vector is network-based, requires no privileges or user interaction, and has high attack complexity — suggesting that exploitation requires specific conditions or knowledge of the alternate path. No user interaction is required, and the vulnerability is exploitable remotely without authentication. Technical write-ups from Rapid7 and Arctic Wolf have analyzed the flaw in the context of its companion vulnerability CVE-2026-18577, noting that the initial patch for CVE-2026-18556 was incomplete and left an alternate bypass path open (Rapid7, Arctic Wolf).
Successful exploitation allows an unauthenticated attacker to gain administrative access to the N-central RMM console — described by researchers as "god mode" access — enabling them to read sensitive data and modify system configuration. Because N-central is used by MSPs to manage endpoints across multiple client organizations, a compromised N-central instance can serve as a pivot point for supply-chain-style attacks against all managed endpoints. N-able confirmed that attackers were able to reach managed endpoints via the flaw, and China-linked threat actors (Storm-1175) have been reported deploying StormEncryptor ransomware through this access path (CISA KEV, Arctic Wolf, N-able Blog).
CVE-2026-18556 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on August 4, 2026, with a due date of August 7, 2026 for federal agencies to remediate (CISA KEV). The EPSS score is approximately 0.27–0.49%, though real-world exploitation has been confirmed. A defensive IOC triage toolkit (not an exploit) was published on GitHub by CreamyG31337 to help defenders detect post-exploitation artifacts (GitHub IOC Toolkit). China-linked threat group Storm-1175 has been attributed to attacks leveraging this vulnerability to deploy StormEncryptor ransomware. The NVD SSVC assessment classifies exploitation as "active" and the vulnerability as "automatable" (Rescana, N-able Blog).
N-able released a security update addressing CVE-2026-18556 and the related CVE-2026-18577 on August 2, 2026, followed by a second hotfix (Hotfix 2) as attackers continued to exploit an incomplete initial patch. Organizations should update N-central to a version beyond 2026.1 immediately, applying all available hotfixes as described in N-able's security update blog posts (N-able Blog). CISA directed federal agencies to remediate by August 7, 2026, per BOD 26-04 guidance. As interim measures, organizations should restrict internet exposure of N-central, monitor for unauthorized administrative sessions, review audit logs for suspicious activity, and verify the integrity of managed endpoint deployments (CISA KEV).
The vulnerability generated significant attention across the security community given N-central's role as a critical MSP management platform. Researchers at Arctic Wolf, Rapid7, ThreatLocker, Field Effect, and eSentire all published advisories and analyses, with ThreatLocker describing the flaw as granting attackers "god mode" access to the RMM console (Arctic Wolf, Rapid7). The Hacker News, SecurityWeek, BleepingComputer, and GovInfoSecurity covered the story extensively, with GovInfoSecurity characterizing the flaw as a "worst-case scenario" for MSPs. The Water ISAC issued a TLP:CLEAR vulnerability notification, and Canada's CCCS published a security advisory. Community discussion on Reddit and Mastodon highlighted urgency around patching, and the incomplete initial patch drew criticism, with one blog post titled "Three fixes shipped in six days, none of them made the thing safe." China-linked threat actor attribution (Storm-1175/StormEncryptor ransomware) further elevated the severity of community response (SecurityWeek, BleepingComputer).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."