Legacy Core™
Official GuidanceArchived record

CISA adds a second N-able N-central vulnerability to the KEV Catalog

CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.

This record is retained for review history. It is not presented as the latest update. Confirm current requirements with the official source.
Official source
Cybersecurity and Infrastructure Security Agency ↗
Jurisdiction
United States
Publication date
August 4, 2026
Legacy Core review
August 17, 2026 · Christopher Green
Source checked
August 17, 2026
Affected sectors
Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
Deadline date
August 7, 2026

Summary

CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.

Why it matters

Small businesses that use N-central directly or through a managed service provider should confirm whether their environment is affected. An authentication bypass means an attacker may not need valid credentials. Catalog inclusion does not establish that every organization uses the product or has been compromised.

Recommended action

Ask your IT owner or managed service provider whether N-central is present and whether vendor mitigations for both CVE-2026-18556 and CVE-2026-18577 have been applied. Keep the response with your security-maintenance records.

CISA adds a second N-able N-central vulnerability to the KEV Catalog | Legacy Core Intelligence | Legacy Core