Field Notes / Threat Intelligence
RMM Security: The Vendor Said the Patch Would Not Remove Whoever Was Already Inside
Five N-central CVEs landed between 1 August and 6 September 2026, and N-able shipped four hotfixes in thirty-five days. The part that matters for an MSP is not the CVSS score. It is the sentence N-able wrote on its own blog: applying the hotfix closes the way in, and leaves a threat actor who is already present exactly where they are. Here is the published chain, what one foothold became inside a single estate, and the exercise that answers the question your client will ask you next.
01 What the attackers actually did
N-able's account of the discovery is short. On 31 July 2026 its Adlumin MDR service "detected unusual activity inside a customer environment and identified a threat actor actively exploiting a previously unknown vulnerability in N-central" N-able, 10 Aug 2026 . Four steps follow, and every one of them is documented by a vendor rather than reconstructed from press coverage.
- Reconnaissance against the API. Huntress logged requests to the endpoint
/remoteControlAction.do?method=getPierDetailsand told defenders to filter their logs for successful requests to internal API routes using URL-encoded values such as%2FHuntress . - Authentication bypass to the console. N-able describes a flaw "that allowed remote administrative access without authentication" N-able, 10 Aug 2026 . Rapid7 confirms the same path and names the affected builds, everything prior to 2026.3.1.10 for CVE-2026-18577, which N-able first moved against with Hotfix 1 on 2 August N-able status, HF1 Rapid7 ETR .
- Take Control, into managed endpoints. Huntress names sessions initiated under the account "MSP Support" as a primary indicator, especially against "domain controllers, file servers, and other high-value systems" at odd hours with no matching support ticket Huntress .
- Cloudflare tunnels for persistence. Registered on the managed devices themselves, so revoking N-central access did not end the intrusion N-able, 10 Aug 2026 .
Sophos supplies the part that should hold an MSP owner's attention. In one
compromised organisation, breached at approximately 08:00 UTC on 3 August
2026, the attacker installed six remote-access tools: AnyDesk, TacticalRMM
v2.11.0, TeamViewer, RustDesk, SimpleHelp and HopToDesk. They added a
Cloudflare tunnel binary renamed to MicrosoftEdgeUpdate64.exe
or msmp.exe, deployed an EDR evasion tool called
PhantomKiller, created a domain account named veeam, reset
administrator passwords and enumerated domain admins
Sophos . Six remote-access tools in
one estate is what a single management-plane foothold turns into when nobody
is watching the egress.
Keep the scale honest, because nobody has published a victim count. Huntress reported exploitation "impacting one organization in our customer base" Huntress . Sophos "identified a single compromised organization in Sophos customer telemetry and have observed no evidence that compromises are widespread" Sophos . N-able, updating its September post on the 9th, said "we've observed a handful of successful exploits against N-central customers" N-able, 5 Sep 2026 . There is no figure for downstream businesses affected, and anyone quoting one has multiplied two numbers together.
02 The incomplete patch, not the CVSS score
The headline number in this story is CVE-2026-86218, a pre-authentication remote code execution flaw in N-central before build 2026.3.1.14. N-able, as the CNA, scores it 10.0 critical on CVSS 4.0. NVD, as primary, scores the same flaw 9.8 critical on CVSS 3.1 NVD, CVE-2026-86218 . Both are real. Quote whichever you like, and name the scale you took it from.
The more useful record is the one directly above it. The original flaw, CVE-2026-18556, is an "authentication bypass using an alternate path or channel" affecting N-central through 2026.1 NVD, CVE-2026-18556 . NVD then describes CVE-2026-18577 in a single line: "An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1" NVD, CVE-2026-18577 . CISA carries the same finding in its catalogue entry, which reads "this vulnerability is the result of an incomplete patch for CVE-2026-18556" CISA KEV . A fix was applied. The flaw stayed open. That gap was found by an attacker before it was found by a retest.
That is the whole argument for re-testing after remediation, written by the CVE record rather than by a security vendor's marketing team. A test that runs once a year produces a report, a remediation sprint and a closing email. Nobody goes back to check that the patch did what the ticket said. When the fix is incomplete, the finding reopens silently and the report on file still says it was closed.
CISA's catalogue gives you the clock. CVE-2026-18577 was added on 3 August with a federal remediation deadline of 6 August. CVE-2026-18556 was added on 4 August, due 7 August. CVE-2026-86218 was added on 8 September, due 11 September. Three days each, and all three entries carry CISA's forensic triage requirement, which means agencies must look for evidence of compromise rather than only patch CISA KEV . Three days is the number to put in front of a client who asks what "urgent" means.
One more line from the same catalogue, because it reframes the month. N-central was already there a year earlier: CVE-2025-8875 and CVE-2025-8876, both added on 13 August 2025 with a deadline of 20 August CISA KEV . Second August running. This is a product class under sustained attention, and every serious RMM platform sits in it.
03 Blast radius starts at one managed endpoint
An external test tells you whether your public surface holds. It says nothing about what a foothold on a single managed device reaches. That second question is the one this campaign asks, and it is answered by an assumed-breach exercise: the operator begins inside, on one endpoint, with the access a compromised remote-support session would hand over.
The exercise measures five things, in this order. Which credentials and tokens sit on that device and still work elsewhere. Which management paths accept them, including the RMM agent itself, the remote-access tooling and the identity tenant. How many hops separate that endpoint from a domain controller, and whether any of them raise an alert. Whether an operator can register an outbound tunnel and hold it, which is the specific behaviour N-able documented. And what a client's backup infrastructure looks like from that position, since backups decide whether an incident is expensive or terminal.
Microsoft's write-up of Storm-1175 shows why each hop is worth proving
rather than assuming. The actor pivots to a domain controller with PsExec
and takes the NTDS.dit dump and the SAM hive. It runs a script to recover
passwords from Veeam backup software. It disables Microsoft Defender through
the registry and adds C:\ to the antivirus exclusion path. It
pushes ransomware across the estate with PDQ Deployer and Group Policy, and
exfiltrates with Bandizip and Rclone
Microsoft, Apr 2026 . The same
report describes Cloudflare tunnels "renamed to mimic legitimate binaries
like conhost.exe" used for lateral movement, which is the
N-central tradecraft observed by a different vendor in a different campaign.
The actor moves faster than a review cycle. Microsoft has seen Storm-1175 move from initial access to ransomware deployment "in as little as one day", with many of its attacks running over five to six days Microsoft, Apr 2026 . A quarterly review cycle does not fit inside that window. Knowing in advance which hop fails first does.
04 The remote-management layer is the preferred door
Microsoft Threat Intelligence posted the ransomware connection on 7 August 2026. On 2 August, it said, Storm-1175 began deploying a new ransomware strain called StormEncryptor. Then the careful sentence, which deserves quoting whole: "While Microsoft has not confirmed the vulnerability targeted by Storm-1175 in this campaign, the threat actor is likely exploiting the CVE-2026-18577 authentication bypass vulnerability in N-able, which was disclosed on August 2, 2026 and added to the CISA KEV catalog on August 3, 2026" Microsoft Threat Intelligence . Likely, not confirmed. Keep the word in when you repeat it to a client.
The pattern behind that hedge is firmer. Microsoft has observed Storm-1175 exploiting more than 16 vulnerabilities since 2023, and the named list includes ConnectWise ScreenConnect, SimpleHelp and Ivanti Connect Secure alongside JetBrains TeamCity, GoAnywhere MFT and BeyondTrust Microsoft, Apr 2026 . Three of those are remote-management or remote-support products. The same report notes the actor weaponised CVE-2025-31324 in SAP NetWeaver a day after disclosure, on 25 April 2025, and has used at least three zero-days, two of them a full week before public disclosure.
Microsoft also names the geography. Its April 2026 report describes recent intrusions "heavily impacting healthcare organizations, as well as those in the education, professional services, and finance sectors in Australia, United Kingdom, and United States" Microsoft, Apr 2026 . That is your client list, described by a vendor with no product to sell you.
Set that against what UK businesses actually do. The government's Cyber security breaches survey 2025/2026, fieldwork August to December 2025 across 2,112 UK businesses, found 43 per cent reported a breach or attack in the previous twelve months. Thirteen per cent ran a penetration test. Fifteen per cent reviewed the risks posed by their immediate suppliers, and 6 per cent looked at the wider supply chain DSIT CSBS 2025/26 . You are the immediate supplier that the other 85 per cent did not review.
05 The question your client asks at the next QBR
A client who reads one article about this will arrive with a version of the same question. Were we affected by the N-able thing? Answering "we patched within the window" is true and insufficient, because the vendor already said patching does not evict anyone who got in first.
The answer that holds the account has four parts, and you can write them down before the meeting.
- What we run and which build it is on. Name the platform, the build number, the date you applied it and who confirmed it. If the instance is vendor-hosted, say so; N-able patched its own hosted environments automatically N-able status, HF4 .
- What we looked for afterwards. The specific artefacts, named: a stray
svchost.exein a user's Documents folder, a service called Cloudflared, inbound connections from the four published addresses N-able status, HF1 , and any unrecognised new account, especially one on a .invalid email address N-able, 5 Sep 2026 . Patching alone is a control. Hunting is evidence. - What we proved after we patched. A re-test, dated, showing the fix holds. CVE-2026-18577 exists because a fix did not.
- What we know a foothold reaches. The blast-radius map from a managed endpoint: which hops opened, which alerted, what the tunnel test did.
Part four is the one almost nobody can answer today, and it is the one that separates a supplier from a partner. Getting it needs an independent team, because a team that administers the estate cannot credibly grade it, and because your client's insurer and, before long, the Information Commission will want a name on the report that is not yours. What that regulation will ask an MSP to prove is set out in our note on the Cyber Security and Resilience Bill.
There is one thing you can take into that meeting before anything is scoped. Name a client and we run a free dark web exposure check on their domain: passive collection across forums, marketplaces and breach dumps for credentials already trading, back with you in two business days and addressed to you, so you present it under your own name. Every chain on this page starts with somebody holding a working login. This tells you whether one of your client's is already for sale.
We deliver CREST-certified testing under your brand, with twelve months of re-tests on every engagement and a written promise never to contact your client. The assumed-breach exercise described here is the one we would run first on an MSP estate, on yours and then on the accounts you choose. Tell us what you buy today and which supplier you buy it from. An operator reads it, and replies with the itemised terms within two working days.
References
Sources
- NIST National Vulnerability Database. CVE-2026-18556, N-able N-central authentication bypass. Published 1 August 2026. nvd.nist.gov
- NIST National Vulnerability Database. CVE-2026-18577, incomplete patch for CVE-2026-18556. Published 2 August 2026. nvd.nist.gov
- NIST National Vulnerability Database. CVE-2026-86218, N-central pre-authentication remote code execution. Published 6 September 2026. nvd.nist.gov
- CISA. Known Exploited Vulnerabilities Catalog, JSON feed, version 2026.09.18, released 18 September 2026. cisa.gov
- N-able. N-central security update, 10 August 2026. n-able.com
- N-able status. N-central 2026.3 Hotfix 2, additional mitigation for CVE-2026-18577. Posted 6 August 2026, 19:45. status.n-able.com
- N-able status. N-central 2026.3 Hotfix 1, mitigation for CVE-2026-18577. Posted 2 August 2026, 22:34. status.n-able.com
- N-able status. N-central 2026.3 Hotfix 4, CVE-2026-86218. Posted 6 September 2026. status.n-able.com
- N-able. N-central security hotfix, 5 September 2026. Page last updated 9 September 2026, 13:49 UTC. n-able.com
- Huntress. N-able N-central vulnerability exploitation. Live-updated write-up, last updated 6 September 2026. huntress.com
- Rapid7. Emergent threat report: CVE-2026-18577 N-able N-central authentication bypass exploited in the wild. Posted 4 August 2026, updated 9 September 2026. rapid7.com
- Sophos. N-able N-central exploitation results in RMM tool deployment. Analysis of a single compromised organisation, breached 3 August 2026. sophos.com
- Microsoft Threat Intelligence. Storm-1175 and StormEncryptor, thread posted 7 August 2026, 21:32 to 21:40 UTC. bsky.app
- Microsoft Security Blog. Storm-1175 focuses gaze on vulnerable web-facing assets in high-tempo Medusa ransomware operations. Published 6 April 2026. microsoft.com
- DSIT and Home Office. Cyber security breaches survey 2025/2026. Official statistics published 30 April 2026, fieldwork August to December 2025, 2,112 UK businesses, conducted by Ipsos. gov.uk