N-able N-central Authentication Bypass: What You Need to Know
N-able N-central has a confirmed authentication bypass vulnerability (CVE-2026-18556) that allows attackers to gain administrative access. Users of N-able N-central are advised to upgrade to the latest version and review their authentication mechanisms.
What happened
N-able N-central, a Remote Monitoring and Management (RMM) product, has been found to contain an authentication bypass vulnerability (CVE-2026-18556) that allows attackers to gain administrative access. This vulnerability has been actively exploited in the wild, leading to customer compromises. N-able has released hotfixes to address the issue, with the latest being Hotfix 2, which supersedes Hotfix 1 with additional hardening measures.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog. CISA advises users to upgrade to the latest version of N-able N-central and review their authentication mechanisms for potential bypasses. Indicators of compromise include a file named'svchost.exe' in the device users' documents folder and a registered service named 'Cloudflared'.
N-able has confirmed that threat actors have reached customer networks by exploiting this vulnerability. The attackers used the Take Control feature to connect to systems within the N-central managed environment and registered a new service for a Cloudflare Tunnel to enable persistence. The malicious activity has not been publicly attributed to any known threat actor or group.
How 0Day mitigates this
n-able is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.