Database/Control plane, storage & DevOps

N-able N-central: Incomplete patch for CVE-2026-18556
CVSS 8.1CVE-2026-18577Control plane, storage & DevOpsKnown exploitedcurated
Impact
Incomplete patch for CVE-2026-18556 -> auth bypass and full account takeover
Who can reach it
Network (remote)
What to do
Control-plane: apply the follow-up patch; audit N-central accounts created since
References
Related entries
- N-able N-central: Deserialization of untrusted data allowing local code execution on the RMM serverCVE-2025-8875 · N-able N-centralHigh
- N-able N-central: Authentication bypass using an alternate path or channel on the RMM serverCVE-2026-18556 · N-able N-centralHigh
- N-able N-central: Improper input validationCVE-2025-8876 · N-able N-centralHigh
- VMware Aria Operations (command injection during assisted migration): An unauthenticated attacker injects commandsCVE-2026-22719 · VMware Aria Operations (command injection during assisted migration)High
- OpenStack glance_store: VMware datastore driver sends authentication headers to an attacker-supplied image location hostCVE-2026-51773 · OpenStack glance_store (VMware datastore driver, _retry_request)High
- Ceph RGW: unsigned x-amz-* headers on presigned URLs are honored, letting a URL holder escalate privilegesCVE-2026-54330 · Ceph Object Gateway (RGW SigV4 presigned-URL header validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.