Critical 9.8
KEV-listed
CVE-2026-18556
Multiple CVEs actively exploited in N-central, Apache Tomcat, and Langflow
Vendor / product: N-able N-central, Apache Tomcat, Langflow, Citrix NetScaler, Marimo Notebook
Event date: 2026-07-30
Victim organization: MSP's clients
Public PoC: Yes
First tracked by RiskWire: 2026-07-28
CISA KEV catalog
Added to KEV
Federal remediation due
2026-08-07 (44 days overdue)
Ransomware campaign use
Unknown
CISA description
N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Named threat actors
knaitheKnYuanJADEPUFFER agent
Sources & citations (43)
- N-central's Incomplete Patch Left MSP Clients Exposed While Attackers Held Both Keys techtimes.com · 2026-08-05
- Security Check-in Quick Hits: Metabase Zero-Day, N-central RMM Breaches & LoadMaster KEV Escalation rodtrent.substack.com · 2026-08-09
- N-able urges customers to patch auth bypass flaw, BleepingComputer reports markets.businessinsider.com · 2026-08-03
- N-central CVE-2026-18577: Patch and Check for Compromise blog.gridinsoft.com · 2026-08-03
- N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577 helpnetsecurity.com · 2026-08-10
- Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) helpnetsecurity.com · 2026-08-03
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises thehackernews.com · 2026-08-04
- N-able N-central exploitation results in RMM tool deployment sophos.com · 2026-08-04
- N-able N-central Bypass Exploited: Patch to 2026.3.1.7 Now sqmagazine.co.uk · 2026-08-03
- N-Able Flaw Exposes MSPs to Worst Case Scenario bankinfosecurity.com · 2026-08-03
- U.S. CISA adds a N-able N-central flaw to its Known Exploited Vulnerabilities catalog securityaffairs.com · 2026-08-04
- Warning: Actively Exploited Vulnerability in N-Central, Patch Immediately! ccb.belgium.be · 2026-08-03
- N-able warns of N-central auth bypass flaw exploited in attacks bleepingcomputer.com · 2026-08-03
- CISA Adds Exploited N-able N-central Flaw Enabling Remote Admin Takeover to KEV gbhackers.com · 2026-08-04
- N-able N-central Auth Bypass Exploited in the Wild After First Patch Missed an Alternate Path dev.to · 2026-08-03
- Attackers Exploit N-able Patch Bypass Flaw on RMM Servers darkreading.com · 2026-08-03
- CVE-2026-18556 / CVE-2026-18577 arcticwolf.com · 2026-08-03
- CISA Warns of N-able N-central Authentication Bypass Vulnerability Exploited in Attacks cybersecuritynews.com · 2026-08-04
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete thehackernews.com · 2026-08-03
- Critical N-able N-central Flaw Actively Exploited to Gain God-Mode Access to MSP Networks gbhackers.com · 2026-08-03
+23 more sources
References
See CVE-2026-18556 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →