The Patch Wasn't the Fix: Lessons from the N-able N-central Takeover
William “BJ” Pote
CEO, eTop Technology
Last week brought the clearest recent example of the attack pattern we think business owners underestimate most: attackers took over N-able N-central servers — a remote monitoring and management (RMM) platform that IT providers use to run their clients’ computers — and used that access to plant persistent backdoors on the endpoints those servers managed.
We wrote earlier this year about what happens when your IT provider gets hijacked and the questions to ask about RMM security. This incident is that post playing out in real time, with two new lessons attached. Here’s the plain-English version.
What actually happened
N-central is management software. An IT provider (or an internal IT department) runs an N-central server, and every computer it manages runs an agent that takes instructions from that server — install this update, run this script, restart that service. By design, the server has administrative control over every machine it manages. That’s the product.
The short timeline, per reporting on the incident:
- An authentication bypass (CVE-2026-18556) allowed unauthenticated administrative takeover of N-central servers — no password, no phishing, just a request to a vulnerable server.
- N-able patched it. Then researchers found an alternative path to the same flaw that the first patch didn’t block (CVE-2026-18577), and N-able shipped an emergency hotfix on August 2.
- CISA added the flaw to its Known Exploited Vulnerabilities catalog after real-world compromises were confirmed.
- On compromised servers, attackers didn’t stop at the server. Security researchers at Huntress found they pushed Cloudflare tunnel software to the managed endpoints, installed as a persistent service — a quiet, legitimate-looking backdoor onto the client machines themselves — at organizations reached through a compromised instance.
Read that last point again, because it’s the part that matters most. Patching the server closes the door the attacker came through. It does nothing about the backdoors the attacker already installed downstream, on computers belonging to the IT provider’s clients. Those have to be found and removed by hand.
We don’t run N-central. This is still worth your attention.
Full disclosure: N-central is not part of our stack, so this wasn’t our fire drill. But it would be dishonest to frame this as an N-able problem. ScreenConnect, SimpleHelp, Kaseya, and others have all had critical flaws in the last few years — we covered several in the RMM supply chain post. Every RMM platform is a high-value target for exactly the reason this incident demonstrates: compromise one management server, inherit administrative control of every business it manages.
The right takeaway isn’t “avoid vendors that have vulnerabilities.” That list is empty. The right takeaway is that how your IT provider operates their tools — patch speed, monitoring, and honesty when something breaks — matters more than which logo is on the tool.
The two new lessons from this incident
Lesson one: the first patch isn’t always the fix. Organizations that patched promptly when the first advisory dropped were still vulnerable, because the fix was incomplete. The vulnerability was only actually closed by the emergency hotfix weeks later. A provider whose process is “patch once, mark it done” would have stayed exposed while believing they were safe. Vulnerability response is a loop — patch, then keep watching the advisory — not a checkbox.
Lesson two: persistence outlives the patch. The attackers’ first move after taking over a server was to establish access that would survive the server being fixed — legitimate tunneling software, installed as a service, on downstream client machines. This is standard playbook now. It means “we patched” and “we’re clean” are two different claims, and the second one requires actually going and looking at the endpoints. In this incident, remediation explicitly required manually removing the malicious tunnel services from managed machines.
What to ask whoever runs your IT this week
If you outsource IT, send these three questions. They’re specific to this incident and the answers are revealing:
- “Do we have any exposure to N-able N-central, directly or through any subcontractor or co-managed arrangement?” If yes: “Are we on the fixed build, and have our endpoints been checked for unauthorized tunnel or remote-access services?”
- “When your RMM vendor publishes a critical advisory, what’s your target time to patch, and who watches for follow-up advisories?” This incident is the argument for why the second half of that question matters.
- “How would you detect a new persistent service — like tunneling software — appearing on our machines?” The honest answers involve endpoint detection and response with someone actually watching it. We explain what that looks like in our EDR explainer.
If you have internal IT running your own RMM or remote-access tooling, the same questions apply — just pointed inward. And if any tool in that category is reachable from the open internet without multi-factor authentication in front of it, that’s the finding; fix that before anything else.
The bottom line
The tools that make modern IT support possible — remote management, remote access, automated patching — concentrate administrative power by design, and attackers have fully absorbed that this makes them the best target in the building. This week it was N-central. It has been ScreenConnect and SimpleHelp before, and it will be another one next.
You can’t pick a vendor that will never have a vulnerability. You can pick a provider that patches in hours, watches for the follow-up advisory, monitors the endpoints for what slips through, and tells you plainly when something affects you. If you don’t know which kind you have, book an intro call — qualifying businesses receive our $2,500 IT Risk Assessment complimentary, and part of that assessment is looking at exactly this: who has administrative reach into your environment, through what tools, and how well-guarded that reach actually is.
William “BJ” Pote
CEO, eTop Technology
eTop Technology has spent over 15 years in IT and over 12 years serving the Inland Empire as a trusted managed IT provider. We host the Business Tech Playbook podcast and are passionate about helping business leaders make smarter technology decisions.