🔴 Critical  |  Source: CISA Known Exploited Vulnerabilities


A critical authentication bypass vulnerability has been identified in N-able N-central, a widely used remote monitoring and management (RMM) platform. Attackers can circumvent authentication controls via an alternate path or channel, potentially gaining unauthorised access to managed endpoints. This is actively exploited in the wild, as confirmed by CISA’s inclusion in the Known Exploited Vulnerabilities catalogue.

Security Architect’s Take: If N-able N-central is deployed in your environment, prioritise patching immediately ahead of the 7 August 2026 deadline and review access logs for signs of unauthorised authentication attempts. Consider isolating N-central management infrastructure behind a VPN or zero-trust access control until the patch is applied, given the platform’s privileged access to managed endpoints.

Original advisory: CVE-2026-18556: N-able N-central