SECURITY ADVISORY: Authentication Bypass Vulnerability in N-Able N-Central
N-able disclosed a high-severity authentication bypass vulnerability (CVE-2026-18556) affecting N-central version 2026.1 and earlier.
Bottom line: ISI uses an affected version of N-central. We have found no evidence that our environment or customer environments have been compromised.
Action Required: None at this time. We will notify customers if our assessment changes or additional action is required.
WHAT'S HAPPENING
N-able disclosed on August 1, 2026, that attackers had identified an authentication bypass vulnerability (CVE-2026-18556, CVSS 8.2) affecting N-central servers running version 2026.1 and earlier.
According to N-able, the attacker gained administrative access to affected N-central servers, then used the platform's Take Control feature to reach devices within the managed environment. On compromised devices, the attacker registered a new Cloudflare tunnel service, which allowed continued access even after access to the N-central server itself was cut off.
N-able has stated that a limited number of customers have been confirmed impacted, and that those customers have been contacted directly.
We have confirmed that we are running an affected version of N-central but have not been contacted directly by N-able nor have we seen any evidence of our deployment being impacted.
WHY THIS MATTERS
N-central is the platform we use to manage and monitor devices across the environments we support. A vulnerability at this layer is not the same as a vulnerability on a single endpoint, it sits closer to the center of how we operate.
This does not mean your environment has been accessed or affected. It means the platform sits in a position where, if left unpatched, it could be used as a path into managed environments.
WHAT WE'RE DOING
1. We checked our environment against every indicator of compromise N-able has published. No matches were found.
2. We are reviewing platform activity logs for signs of the specific technique used in this attack, unauthorized remote access sessions and unexpected persistence mechanisms.
3. We have implemented additional restrictions on the affected platform.
4. We are planning a controlled upgrade to a patched version, with backups verified beforehand.
No action is required on your part at this time.
WHAT TO WATCH FOR
Be alert for:
- Unexpected remote access activity on your devices
- Unfamiliar software or services you did not install
- Devices behaving differently than expected, slow performance, unexpected reboots, or unusual network activity
- Any communication claiming to be from ISI that asks you to take urgent action outside of normal processes
WHAT TO DO IF YOU SUSPECT A PROBLEM
If you notice anything unusual, contact ISI support directly at support@isidefense.com or call the helpdesk at (202) 792-3042. We will investigate and respond according to our incident response process.
WHAT ISI CAN DO TO HELP
We are actively monitoring this situation and will follow up once the upgrade is complete and our review is closed. In the meantime, our team is available to answer questions about this advisory or your specific environment.
Stay safe, stay secure.
-ISI Cybersecurity Team


