Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-08-23 ยท updated: 2026-08-23 ยท tags: [cve, rmm, active-exploitation, acsc-alert, supply-chain] ยท confidence: high ยท severity: critical ยท affected_sectors: [technology, government, finance, critical-infrastructure] ยท au_impact: true

CVE-2026-18556 is one of two vulnerabilities in N-able/N-central remote monitoring and management (RMM) software under active exploitation in Australia. The Australian Cyber Security Centre issued a High-rated alert on 19 August 2026 warning of active exploitation of this flaw alongside CVE-2026-18577, directing Australian organisations across business, critical infrastructure and government to assess exposure and apply mitigations. This was a rare AU-first active-threat warning on an RMM product class long targeted by Australian campaigns. Patching the N-central server alone does not complete remediation while attacker-planted tunnel services may remain on managed endpoints.