← All posts
cybersecurityRMMpatch managementvulnerability managementN-central

When Your MSP's Own Tools Get Targeted: The N-central Vulnerability, Explained

MFMike FarmerAugust 6, 2026 · 3 min read

Most cybersecurity stories are about vulnerabilities in software you use. This one is about a vulnerability in software your MSP uses to keep an eye on your network, and it's worth walking through both because of what happened and because of what it says about how we handle situations like this.

What happened

On July 31, N-able's own threat detection team caught unusual activity inside a customer environment and traced it to a zero-day authentication bypass in N-central, the remote monitoring and management (RMM) platform we and thousands of other MSPs use to manage client endpoints. Attackers who exploited the flaw could skip the login screen entirely and gain administrative control of an N-central server, then use its built-in remote access features to reach the endpoints it manages.

N-able had actually patched a related issue earlier, in the 2026.2 release, tracked as CVE-2026-18556. That fix turned out to be incomplete: attackers found a second way through the same door, tracked separately as CVE-2026-18577. N-able shipped a real fix, version 2026.3.1 Hotfix 1 (build 2026.3.1.7), on August 2. CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 3, which is federal shorthand for "this is being actively used against real targets, patch it now."

The attackers' playbook was patient. Once inside, they used N-central's Take Control feature to reach managed devices, then registered Cloudflare Tunnel connections as a backdoor, so even if their initial access got cut off, they had a second way back in.

Why this matters even if you've never heard of N-central

RMM platforms are high-value targets precisely because of what they're built to do: one login gives an attacker visibility and control across every endpoint that platform manages, sometimes across hundreds of client businesses at once. That's the same efficiency that makes an MSP valuable to you in the first place. It cuts both ways, and it's exactly why the security of our own management stack, not just your firewalls and endpoints, has to be part of the conversation.

What we did

Our N-central environment was updated within hours of the fix shipping, and we didn't just take that on faith. We confirmed the hotfix had landed on our own instance and verified the same across every environment we manage on behalf of clients, well ahead of the public advisory and most of the news coverage that followed. We also followed N-able's guidance to review access logs and run its indicator-of-compromise scans against managed endpoints. That's standard practice for us whenever a vendor we depend on ships an emergency patch: verify it's in place, check for signs of trouble, then communicate.

The takeaway

This wasn't a failure of imagination on N-able's part. Authentication bypass bugs happen even to mature, well-run platforms, and a zero-day means there's no patch to apply until the vendor ships one. What matters is what happens in the hours after a vendor discloses a flaw like this: whether someone is watching for it, whether the patch actually gets applied, and whether anyone checks for signs of compromise instead of just assuming a clean bill of health. That's the job, on our tools as much as yours.

If you have questions about how this affects your environment specifically, or want to talk through your own patch management process, reach out. We're happy to walk through it.

Want this reviewed against your environment?

We'll walk your stack with you and tell you plainly what we'd change first.