Knox CVE Database
/
CVE-2026-18556
High
7.4

CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

Added to the CISA KEV catalog:
August 4, 2026

Overview

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.

This issue affects N-central: through 2026.1.

Vulnerability details

Affected vendor
N-able
Affected product
N-central
Weakness type (CWE)
CWE-288

N-central contains an authentication bypass via an alternate path or channel (CWE-288), a weakness class where a privileged function or interface is reachable through a path that does not enforce the product's normal credential checks. Rather than breaking the authentication mechanism directly, an attacker reaches administrative functionality through a channel the authentication gate does not cover. In N-central, a remote management platform used by managed service providers to administer large fleets of endpoints, this class of flaw carries outsized risk because administrative access to the platform translates directly into access to every managed device beneath it.


An attacker with network access to the N-central management interface sends crafted requests to the alternate, unauthenticated path, obtaining full remote administrative access without credentials. The specific endpoint or channel has not been disclosed by the vendor, who deferred full root-cause analysis while the investigation remained active. Once inside, the attacker can use N-central's built-in Take Control feature to connect to managed endpoints. In the confirmed exploitation observed by N-able's Adlumin MDR team, threat actors registered Cloudflare tunnel services on managed devices to maintain persistence even after their N-central access was revoked.

Severity and impact

7.4
High
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality impact
High
Integrity impact
High
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review N-central administrative session logs for authenticated admin sessions that have no corresponding login event through the normal credential path, particularly sessions initiating Take Control connections to managed endpoints.
  • Monitor managed endpoints for new Cloudflare tunnel service registrations (cloudflared process execution or new tunnel service entries) that were not initiated by a known administrator, as this was the persistence mechanism used in confirmed exploitation.
  • Audit N-central audit trails for Take Control sessions initiated outside normal maintenance windows or targeting large numbers of endpoints in rapid succession, which would be anomalous relative to typical MSP operational patterns.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 7, 2026

Additional hardening

  • Restrict network access to the N-central management interface to known administrator source IP ranges using firewall rules or a VPN gateway, reducing the attack surface for unauthenticated path access.
  • Apply Hotfix 2 (2026.3.1.10) immediately, as it supersedes Hotfix 1 and addresses a related attack path identified during continued post-incident monitoring.
  • Audit all managed endpoints for unauthorized Cloudflare tunnel service registrations and remove any tunnels not provisioned through a documented change process, as persistence may survive N-central access revocation.
  • Enforce least-privilege role assignments within N-central so that compromised sessions have the narrowest possible scope over managed device groups.

Key dates

Published (NVD)
August 1, 2026
Added to CISA KEV
August 4, 2026
Remediation deadline
August 7, 2026
Last updated
August 5, 2026

References

Frequently asked questions

Does CVE-2026-18556 affect my FedRAMP authorization?

If N-able N-central runs inside your authorization boundary, CVE-2026-18556 is your problem. CISA has listed this authentication bypass vulnerability in the Known Exploited Vulnerabilities (KEV) catalog, with a remediation deadline of August 7, 2026. An unpatched KEV inside a FedRAMP boundary is a finding: your assessor and sponsoring agency will raise it, and you will need to remediate it or formally document a mitigation before that conversation happens.

How does Knox help me handle CVE-2026-18556?

Remediating N-able N-central is your responsibility under the FedRAMP shared-responsibility model. Knox does not patch your software. What Knox provides is the pre-authorized, single-tenant boundary in which you carry out that remediation, plus continuous compliance monitoring and audit-artifact coverage to document the fix for your next assessment. The work of applying the patch is yours; managing your compliance posture while you do it is not something you have to handle on your own.

How does Knox's monitoring help with vulnerabilities like this?

Knox's automated continuous monitoring platform watches your environment for newly disclosed vulnerabilities and compliance issues on an ongoing basis. When something like CVE-2026-18556 surfaces, exposure is identified through continuous monitoring rather than surfacing for the first time during an assessor review, giving you time to act before it becomes a formal finding.

How do I get FedRAMP authorized with Knox?

Knox runs a FedRAMP-as-a-Service platform. It gives SaaS vendors a pre-authorized cloud boundary on AWS, Azure, and GCP. Your application inherits 60–80% of the required security controls. You reach FedRAMP authorization in about 90 days for roughly 90% less than the traditional $3.5M path. Book a meeting and Knox will map your path to authorization.

What happens if CVE-2026-18556 isn't remediated by August 7, 2026?

If you miss the August 7, 2026 deadline, CVE-2026-18556 becomes a Plan of Action and Milestones (POA&M) item. A growing POA&M list turns a routine continuous-monitoring review into a hard conversation with your agency. Hitting the deadline keeps your authorization clean.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting