Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Urgent: Security Flaw in N-able N-central Could Let Hackers Bypass Login

A serious security weakness has been found in N-able N-central software that could allow attackers to bypass normal login controls. This flaw is actively being exploited, meaning hackers are using it to break into systems. Small organisations using this software should act quickly to reduce risk.

05 August 2026

Reference: CVE-2026-18556

1. What is being reported?

The vulnerability allows attackers to bypass authentication in N-able N-central by using an alternate method to access the system without proper login. This means someone could gain control without needing valid credentials.

2. What this means in plain English

If your organisation uses N-able N-central, attackers might be able to access your system remotely without permission. This could lead to data theft, disruption of services, or other harmful actions.

3. Could this affect a small business?

Small businesses or charities using N-able N-central, especially if it is accessible over the internet, are at risk. Those not using this software or who have it isolated from external access are less likely to be affected.

4. What to do now

  • Contact your IT provider or software supplier immediately to check if you use N-able N-central and confirm your version.
  • Apply any security updates or mitigations provided by N-able as soon as possible.
  • Review whether N-able N-central is exposed to the internet and restrict access if possible.
  • Follow any additional guidance from your IT provider regarding monitoring and incident response.

5. Ask your IT provider

Can you confirm if we use N-able N-central and if so, have the latest security updates or mitigations for CVE-2026-18556 been applied to prevent authentication bypass?

6. Bottom line

If you use N-able N-central, act now to secure it against a known and actively exploited login bypass vulnerability.

Information based on CISA KEV, NVD, and multiple reputable security reports.

Back to Vulnerability Briefs