Your IT Company's Management Tool Just Became a Master Key. Here's What the N-able Breach Means for Every Business.
Attackers bypassed authentication in N-central, the RMM platform MSPs use to manage thousands of client environments. If your IT provider uses N-central — and didn't patch by August 2 — every device they manage was potentially reachable.
Most businesses don't know what an RMM platform is. They probably should.
RMM stands for Remote Monitoring and Management. It's the software your managed IT service provider uses to monitor your servers, push patches, run scripts, and access your devices remotely. Think of it as a master key — one console that can reach every endpoint across every client the MSP manages.
This past week, a company called N-able confirmed that attackers broke into that master key. And the first fix didn't work.
What Happened
N-able makes N-central, one of the most widely deployed RMM platforms in the managed services industry. On August 1–2, 2026, N-able disclosed a critical vulnerability in N-central — actually two related vulnerabilities, CVE-2026-18556 and CVE-2026-18577 — that allowed attackers to gain full administrative access to the N-central console without any valid credentials. No username. No password. No authentication required.
Here's the part that should make you stop and read this twice: N-able issued a first fix, told customers they were safe if they upgraded to version 2026.3, and then discovered the fix was incomplete. Attackers had already found a second exploitation path through the same underlying weakness. The truly safe version — 2026.3.1.7 — wasn't released until August 2.
Meanwhile, active exploitation was confirmed. Attackers were already inside.
What Attackers Did With the Access
Once inside an N-central console, attackers had the same capabilities as a trusted MSP administrator. That's not theoretical — it's what confirmed exploitation looked like:
- They used N-central's built-in Take Control feature to remotely access managed endpoints across client environments. - On those machines, they installed Cloudflare tunnels registered as Windows services — persistent backdoors that survive reboots and require no inbound firewall rules. The traffic looks like normal outbound internet activity. - The tunnels preserved access even after the N-central server route was patched and revoked.
This matters enormously. An attacker who compromised an MSP's N-central server didn't just get access to the MSP — they potentially got access to every client the MSP manages. One breach, thousands of downstream targets.
And critically: patching N-central does not remove the Cloudflare tunnel backdoors already installed on endpoint machines. Every organization whose MSP ran N-central needs to check their devices, not just wait for the all-clear from their vendor.
The MSP Trust Problem
This isn't the first time MSPs have been used as an attack vector, and it won't be the last. In 2021, the Kaseya VSA incident exposed MSP clients to REvil ransomware at scale. The pattern repeats because the economics are attractive to attackers: compromise one management platform, reach thousands of businesses simultaneously.
The trust relationship between a business and its MSP is, by design, deep. MSPs need remote access to your systems to do their job. That access creates the exact kind of high-privilege, broadly connected entry point that attackers prize.
None of this means you should fire your MSP. It means you should ask better questions.
The Questions Every Business Leader Needs to Ask Right Now
If your organization uses a managed IT service provider, here are the three conversations to have immediately:
First: Does your MSP use N-central? What is their current version?
N-able confirmed that all versions prior to 2026.3.1.7 are vulnerable, including versions that received the first (incomplete) patch. Cloud-hosted instances were updated automatically on a schedule; self-hosted servers require manual action. Your MSP should be able to confirm their current build without hesitation. If they can't answer that question clearly and immediately, that tells you something.
Second: Has your MSP audited for Cloudflare tunnel persistence on your endpoints?
Upgrading N-central is necessary but not sufficient. If attackers reached your environment before the patch, they may have installed persistent backdoors on your devices that survive the fix. The indicators are specific: look for svchost.exe in user Documents folders, a service named Cloudflared, or network traffic to the known attacker IP addresses. Your MSP should have run this hunt proactively. Ask whether they did.
Third: What is your MSP's breach notification obligation to you?
Your contract with your managed service provider likely contains some language about security incidents. Do you know what it requires them to disclose, and when? A vendor compromise that touches your environment — even indirectly — is your incident. Make sure your agreement requires timely notification. If it doesn't, your next contract renewal is an opportunity to fix that.
The Broader Pattern
There's a theme worth naming here. Over the past several months, we've seen a consistent pattern of attackers targeting the infrastructure layer — the tools, platforms, and management systems that connect businesses to their vendors and service providers.
SharePoint. ServiceNow. N-central. FortiGate firewalls. These aren't your business applications. They're the plumbing behind them. And because that plumbing is broadly deployed, broadly trusted, and often broadly under-monitored, it's become one of the highest-value target categories in modern attacks.
The lesson isn't that these products are inherently dangerous. The lesson is that your security posture can't end at your own network perimeter. The platforms your partners use to access your environment are part of your attack surface, whether you manage them or not.
What to Do This Week
If you use a managed IT provider:
1. Ask whether they use N-central and confirm they're on version 2026.3.1.7 or higher. 2. Ask whether they've audited managed endpoints for the Cloudflare tunnel persistence indicator. 3. Pull your MSP contract and find the security incident notification clause. If it's vague or absent, note it for renewal.
If you are a business leader who doesn't know which RMM platform your IT provider uses, that's the first answer to get. The tool that manages your devices from the outside is one of the most powerful access paths into your environment. You should know what it is, who made it, and whether it was patched.
At TrustPoint Cyber, we help businesses understand not just their own security posture — but the exposure created by the vendors and platforms connected to them. If you're not sure how to have this conversation with your IT provider, we're happy to help you frame it.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.