Knox CVE Database
/
CVE-2026-18556
High
8.2

CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability

N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

Added to the CISA KEV catalog:
August 4, 2026

Overview

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass.

This issue affects N-central: through 2026.1.

Vulnerability details

Affected vendor
N-able
Affected product
N-central
Weakness type (CWE)
CWE-288

N-able N-central contains an authentication bypass via an alternate path or channel (CWE-288), a weakness class where a product exposes a secondary route to a protected function that does not enforce the same authentication controls as the primary path. In N-central, a remote management platform used by managed service providers to administer large fleets of customer endpoints, this means an attacker can reach administrative functionality without supplying valid credentials. The alternate path is not publicly disclosed, but the effect is complete bypass of the authentication boundary protecting the management console.

An attacker with network access to the N-central management interface sends crafted requests to the alternate path, obtaining full administrative access without credentials. No prior knowledge of accounts or tenant configuration is required beyond reachability of the interface. With administrative access established, the attacker can use N-central's built-in Take Control feature to connect directly to any managed device in the customer fleet. Observed post-exploitation included registering Cloudflare tunnel services on managed devices, providing persistent access that survives revocation of the attacker's N-central session. Both hosted and on-premises deployments are affected when the management interface is network-reachable.

Severity and impact

8.2
High
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
None
Scope
Confidentiality impact
High
Integrity impact
None
Availability impact
None

Exploitation status

This vulnerability is confirmed as actively exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.

Known ransomware campaign use
Unknown

Detection and monitoring

  • Review N-central audit logs for administrative sessions, configuration changes, or Take Control activations that have no corresponding authentication event or that originate from IP addresses outside known administrator ranges.
  • Audit managed endpoints for newly registered Cloudflare tunnel processes or services (cloudflared) that were not deployed through an authorized change process, as this was the observed persistence mechanism post-exploitation.
  • Inspect N-central agent activity logs for Take Control sessions initiated during periods when no legitimate administrator was active, particularly sessions touching large numbers of devices in a short window.

Remediation

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Federal (FCEB) remediation due date
August 7, 2026

Additional hardening

  • Restrict network access to the N-central management interface to known administrator IP ranges using firewall rules or a VPN gateway, reducing the attack surface for unauthenticated inbound requests.
  • For on-premises deployments, place the N-central server behind a network segment that is not directly reachable from the internet; require explicit jump-host or VPN access for all administrative connections.
  • Audit all managed endpoints for unauthorized Cloudflare tunnel services (cloudflared) and remove them, as persistence may survive patching if implanted before the hotfix was applied.
  • Apply the vendor-supplied hotfixes in sequence and confirm the installed build matches the current hardened release before restoring any internet-facing exposure of the management interface.

Key dates

Published (NVD)
August 1, 2026
Added to CISA KEV
August 4, 2026
Remediation deadline
August 7, 2026
Last updated
August 5, 2026

References

Frequently asked questions

Does CVE-2026-18556 affect my FedRAMP authorization?

If N-able N-central runs inside your authorization boundary, yes. CVE-2026-18556 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, which carries a remediation deadline of August 7, 2026. For a FedRAMP-authorized service, an unpatched KEV in your boundary is a finding — one you either remediate or formally document a mitigation for before your assessor and sponsoring agency raise it.

How does Knox help me handle CVE-2026-18556?

Knox doesn't patch your software for you — remediating N-able N-central is your responsibility under the FedRAMP shared responsibility model. What Knox gives you is the pre-authorized, single-tenant boundary to remediate in, plus continuous compliance monitoring and audit-artifact coverage that help you document the fix for your next assessment. The fix is yours to apply; staying compliant while you apply it isn't something you manage alone.

How does Knox's monitoring help with vulnerabilities like this?

Knox's continuous monitoring, powered by KnoxAI, watches your environment in real time for newly disclosed vulnerabilities and compliance issues. Exposure surfaces as part of ongoing monitoring — not only when an assessor flags it at review time.

How do I get FedRAMP authorized with Knox?

Book a meeting and Knox maps your path — FedRAMP in 90 days for 90% less, without dependency or delay.

What happens if CVE-2026-18556 isn't remediated by August 7, 2026?

It becomes a POA&M item, and a growing POA&M list is what turns a routine continuous-monitoring review into a real conversation with your agency. Meeting the deadline keeps your authorization clean and the agency relationship intact.

What this vulnerability means for your FedRAMP compliance

Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, FedRAMP continuous monitoring puts a hard remediation clock on it. The clock starts on awareness — and missing the deadline can put an Authority to Operate at risk.

FedRAMP remediation deadlines for actively exploited vulnerabilities

FedRAMP ConMon SLAs give cloud providers 30, 90, or 180 days by severity — but KEV-listed flaws carry the tighter CISA deadline shown above. For authorized services, that date is the compliance line that assessors and agency sponsors will check.

How Knox reduces the burden of CVE vulnerabilities

Remediating the flaw is your responsibility under the FedRAMP shared responsibility model — but staying compliant while you fix it isn't something you manage alone. KnoxAI's continuous monitoring surfaces exposure in real time, and Knox keeps your continuous-monitoring evidence and audit artifacts current while you apply the fix. Learn more about the Knox platform.

How to limit your exposure through inherited controls and isolation

Knox's single-tenant architecture gives every customer a dedicated boundary, and 60–80% of FedRAMP controls are inherited from the platform — shrinking the surface you have to patch and prove. See why teams choose Knox.

Ready to achieve FedRAMP authorization in 90 days or less?

Schedule a meeting to discuss scope, parse readiness, and map your company’s accelerated path to FedRAMP authorization.

Book a Meeting