Rejuvenate IT Logo

Attackers reached client networks through a tool many IT firms use – what to ask your provider

N-able has confirmed that attackers broke into customer networks through a flaw in N-central, the remote monitoring and management platform a great many IT providers use to look after their clients’ computers. The Register reports that the company has now acknowledged attackers reached systems inside the environments its customers were managing.

The flaw, catalogued as CVE-2026-18577, let an attacker with no username and no password gain administrator access to an N-central server. From there they used Take Control, N-central’s built-in remote access feature, to connect to machines on the networks below it. N-able says exploitation has been seen in the wild since 1 August, and that a limited number of customers were affected – it has not said how many.

The American cyber agency CISA added the flaw to its Known Exploited Vulnerabilities catalogue on 3 August and gave federal agencies just three days to patch – the shortest deadline it issues. N-able issued one hotfix on 2 August and a second on 6 August; the second is required even if the first was already installed. Attackers who got in also set up Cloudflare Tunnel services, giving themselves a way back in after being evicted from the N-central server itself.

Who this affects

Almost certainly not you directly. N-central is not something a business buys for itself – it is a tool your IT provider runs. But that is exactly why it matters to you. Remote monitoring software has an agent on every machine it manages, with full administrator rights, because that is how it installs updates and fixes faults without anyone driving out to you. It is, in effect, a master key to every machine in the building.

Put simply: if the company that looks after your IT runs N-central on its own servers, your computers were reachable from something that attackers were confirmed to be inside. Your firewall and your antivirus would have seen nothing wrong, because the connection arrived through a legitimate management tool doing exactly what it is built to do. N-able’s own cloud-hosted instances were patched centrally, so the question that matters is whether your provider runs it on its own servers.

What to ask your IT provider

  • Do you use N-able N-central, and is it self-hosted or N-able’s cloud? A straight answer either way takes one sentence. If they do not use it, you are done.
  • If self-hosted, is Hotfix 2 installed? That is build 2026.3.1.10, released 6 August. Hotfix 1 on its own is not enough – the second one supersedes it.
  • Have you checked for compromise, not just patched? Patching closes the door; it does not tell you whether anyone already walked through it. These are different jobs and the second is the one that matters.
  • Specifically, have you looked for unexpected Take Control sessions and for Cloudflare Tunnel services nobody set up? Those are the two things reported in this campaign.
  • Have administrator accounts and credentials on that server been reviewed and rotated? Anyone who had administrator access could have created accounts of their own.

Since you will ask: we use it too

It would be a bit rich to hand you those five questions without answering them ourselves. So: we do use N-able N-central. Both hotfixes were applied as soon as each one was released, and we were not affected by this incident.

None of this means N-central is a bad choice – every provider runs something like it, and the alternative is nobody watching your machines at all. What it does mean is that the security of your IT partner’s own tools is part of your security, and you are entitled to ask about it. A good provider will answer plainly, without you having to push.

If you would like a second pair of eyes on any of the above, or you are not getting a straight answer from whoever looks after your IT, that is what our managed IT services and managed detection and response are for – including round-the-clock monitoring, so a stranger using a legitimate tool at three in the morning is still noticed.

Call us on 01202 237 273 or book a call.