CVE-2026-18556 and CVE-2026-18577 are authentication bypass vulnerabilities affecting N-able N-central, a remote monitoring and management (RMM) platform used by managed service providers (MSPs) and enterprise IT teams to administer large fleets of endpoints. CVE-2026-18577 exists because the original remediation for CVE-2026-18556 did not fully resolve the underlying authentication logic issue, leaving a residual authentication bypass that attackers could still exploit. Successful exploitation allows an unauthenticated attacker to gain administrative access to the N-central server, which can then be used to compromise managed endpoints. CVE-2026-18556 carries a CVSS v3.1 score of 7.4, while CVE-2026-18577 is rated 8.1. Both vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog. Horizon3.ai’s research team reverse engineered these vulnerabilities and developed Rapid Response tests for NodeZero®.
CVE-2026-18556 is an authentication bypass caused by improper enforcement of authentication controls through an alternate access path. It affects N-central versions through 2026.1.
The initial vendor remediation did not completely eliminate the underlying authentication flaw. As a result, CVE-2026-18577 was assigned to the remaining authentication bypass affecting N-central versions prior to 2026.3 Hotfix 1 (build 2026.3.1.7).
An attacker can remotely authenticate without valid credentials and obtain administrative access to the N-central server. Because N-central manages customer infrastructure and endpoints, a successful compromise allows attackers to leverage built-in administrative capabilities, including remote management functions such as Take Control, to access downstream systems.
Both vulnerabilities have been observed in active exploitation and should be treated as high priority for remediation.
A NodeZero Rapid Response test has been developed to safely validate whether this authentication bypass can be exploited in your environment. The test executes real attack techniques without causing damage, giving teams immediate clarity on exposure.
CVE-2026-18556
CVE-2026-18577
Upgrade to N-central 2026.3 Hotfix 1 (build 2026.3.1.7) or any later vendor-supported release.
If immediate patching is not possible, N-able recommends:
These measures reduce exposure but do not eliminate the vulnerability. Applying the vendor hotfix remains the recommended remediation.
The NodeZero® platform empowers your organization to reduce your security risks by autonomously finding exploitable weaknesses in your network, giving you detailed guidance around how to priortize and fix them, and having you immediately verify that your fixes are effective.