Vulnerability
Published 2026-08-19
Verified 2026-09-19

N-able N-central authentication bypass, exploited in Australia

CVE-2026-18556 and CVE-2026-18577 are authentication-bypass issues in N-able N-central that may allow unauthorised access through an alternate path. ASD's ACSC has observed targeting of the product in Australia. Affects current versions including 2026.3. Vendor Hotfix 2 (build 2026.3.1.10, 6 August 2026) supersedes Hotfix 1. Review whether the console needs to face the internet.

Product
N-able N-central
Versions
Current versions including 2026.3
CVSS
(CVSS 4.0, N-able CNA)
Exploited in Australia?
yes
Patch to
Hotfix 2 (2026.3.1.10)

Primary: ASD's ACSC advisory · Vendor: N-able security update · CVE: CVE-2026-18556, CVE-2026-18577 · Australian Cyber Security Magazine (secondary)

vulnerabilities australia