CISA adds a second N-able N-central vulnerability to the KEV Catalog
CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.
- Official source
- Cybersecurity and Infrastructure Security Agency ↗
- Jurisdiction
- United States
- Publication date
- August 4, 2026
- Legacy Core review
- August 17, 2026 · Christopher Green
- Source checked
- August 17, 2026
- Affected sectors
- Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
- Deadline date
- August 7, 2026
Summary
CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.
Why it matters
Small businesses that use N-central directly or through a managed service provider should confirm whether their environment is affected. An authentication bypass means an attacker may not need valid credentials. Catalog inclusion does not establish that every organization uses the product or has been compromised.
Recommended action
Ask your IT owner or managed service provider whether N-central is present and whether vendor mitigations for both CVE-2026-18556 and CVE-2026-18577 have been applied. Keep the response with your security-maintenance records.