Vulnerability
Published 2026-08-19
Verified 2026-09-19
N-able N-central authentication bypass, exploited in Australia
CVE-2026-18556 and CVE-2026-18577 are authentication-bypass issues in N-able N-central that may allow unauthorised access through an alternate path. ASD's ACSC has observed targeting of the product in Australia. Affects current versions including 2026.3. Vendor Hotfix 2 (build 2026.3.1.10, 6 August 2026) supersedes Hotfix 1. Review whether the console needs to face the internet.
- Product
- N-able N-central
- Versions
- Current versions including 2026.3
- CVSS
- (CVSS 4.0, N-able CNA)
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - Exploited in Australia?
- yes
- Patch to
- Hotfix 2 (2026.3.1.10)
Primary: ASD's ACSC advisory · Vendor: N-able security update · CVE: CVE-2026-18556, CVE-2026-18577 · Australian Cyber Security Magazine (secondary)
