Legacy Core
Official Guidance

CISA adds a second N-able N-central vulnerability to the KEV Catalog

CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.

Official source
Cybersecurity and Infrastructure Security Agency
Jurisdiction
United States
Publication date
August 4, 2026
Legacy Core review
August 17, 2026 · Christopher Green
Source checked
August 17, 2026
Affected sectors
Accounting and Tax, Medical and Dental, Legal, Financial Services, Insurance, General Professional Services
Deadline date
August 7, 2026

Summary

CISA added CVE-2026-18556, an N-able N-central authentication-bypass vulnerability, to its Known Exploited Vulnerabilities Catalog on August 4, 2026. CISA's record for CVE-2026-18577 states that later flaw was the result of an incomplete patch for this one.

Why it matters

Small businesses that use N-central directly or through a managed service provider should confirm whether their environment is affected. An authentication bypass means an attacker may not need valid credentials. Catalog inclusion does not establish that every organization uses the product or has been compromised.

Recommended action

Ask your IT owner or managed service provider whether N-central is present and whether vendor mitigations for both CVE-2026-18556 and CVE-2026-18577 have been applied. Keep the response with your security-maintenance records.

CISA adds a second N-able N-central vulnerability to the KEV Catalog — Legacy Core Intelligence | Legacy Core