🔴 Critical | Source: CISA Known Exploited Vulnerabilities
A critical authentication bypass vulnerability in N-able N-central allows attackers to circumvent login controls and take over accounts without valid credentials. This flaw is particularly concerning because it represents an incomplete fix for a previously patched vulnerability (CVE-2026-18556), meaning organisations that believed they were protected may still be exposed. N-central is widely used by managed service providers to remotely manage client endpoints, so a compromise could have cascading effects across multiple downstream organisations.
Security Architect’s Take: Prioritise patching N-central immediately ahead of the 6 August 2026 CISA remediation deadline, and audit all N-central administrator accounts for signs of unauthorised access or privilege changes. Given the MSP supply-chain risk, also notify any downstream clients managed via the platform and consider restricting N-central’s management interface to trusted IP ranges until patching is confirmed.
Original advisory: CVE-2026-18577: N-able N-central