N-able N-central attacks: is your IT provider the way in?

By Greg Markowski / Sep 6, 2026 / Epic IT News

On 19 August, the ACSC sent out a high alert marked “act quickly”. Attackers are actively exploiting two vulnerabilities in N-able N-central, a remote monitoring and management platform, and they are doing it here in Australia. If you have never heard of N-central, that is exactly the problem. Your IT provider probably has, because tools like it are how MSPs manage your entire business.

This is the alert we have been telling clients to expect. Attackers stopped kicking down individual front doors years ago. Breaching one MSP’s management console opens every client behind it, and the N-able N-central vulnerability alert is the clearest local proof yet that criminals know it.

What the N-able N-central vulnerability alert actually says

The ACSC alert names two flaws: CVE-2026-18556 and CVE-2026-18577. Both are authentication bypass vulnerabilities scored 8.2 (high severity), and both may allow unauthorised access through an alternate path or channel. In plain English: a way in that does not require anyone’s password.

The vulnerabilities affect all current versions of N-central, including 2026.3. N-able released patches on 1 August and a follow-up Hotfix 2 on 6 August, and the ACSC says organisations should upgrade to Hotfix 2 as a priority. The vendor has also published indicator of compromise detection scripts, which matters because patching closes the door but does not evict anyone who already walked through it.

Two details in the alert deserve your attention. First, the ACSC has observed active exploitation within Australia. This is not a theoretical advisory about something happening overseas. Second, the ACSC explicitly advises that small and medium businesses should ask their MSP whether they use the product. The government is telling you, the business owner, to question your IT provider. We think you should take them up on it.

Why an RMM breach is worse than a normal breach

A remote monitoring and management platform is the tool an IT provider uses to see and control every device it manages. Deploy software to 500 machines at once. Run scripts with administrator rights. Reset passwords. Disable security tools. Push updates. All from one console.

That is precisely what makes an RMM the highest-value target in the managed services world. An attacker who compromises a single business gets one business. An attacker who compromises an MSP’s RMM console gets every client that MSP manages, with legitimate administrator access that endpoint detection and response tools are configured to trust. The malicious activity arrives through the same channel your normal IT support does.

There is something genuinely uncomfortable about this for our industry. The tools that make managed IT affordable are the same tools that concentrate risk. Any MSP that pretends otherwise is not being straight with you.

This has happened before, at scale

In July 2021, the REvil ransomware group exploited Kaseya VSA, another RMM platform, and used it to push ransomware through roughly 60 MSPs to as many as 1,500 downstream businesses in a single weekend. Most of those businesses had never heard of Kaseya. They were encrypted anyway, because their IT provider’s tooling was the delivery mechanism.

Since then, RMM and remote access tools have been hit repeatedly, and intelligence agencies across the Five Eyes have warned that state and criminal actors deliberately target MSPs to reach their clients. The N-central campaign is not an anomaly. It is the current instalment of a pattern that is now five years old and getting worse, for a simple reason: it works.

We run tools like this too. Here is how we think about it

Full disclosure: Epic IT does not use N-able N-central, so our clients are not exposed to these specific CVEs through us.

We are not going to gloat about that, because it would be dishonest. Every MSP runs remote management tooling of some kind, us included, and every one of those platforms is a high-value target. The difference between a safe provider and a dangerous one is not which product they bought. It is how seriously they treat their own attack surface. We deliberately do not publish which platforms we run, for the same reason you would not publish a map of your office keys.

When the ACSC alert landed, our response was not relief. It was a prompt to re-check our own house: confirm our tooling is current, review who holds console access, verify phishing-resistant MFA is enforced on every administrative account, and check our vendors’ security advisories for anything similar brewing. We hold our own tooling to the same Essential Eight patching timelines we implement for clients, because an MSP that patches client systems within 48 hours but lets its own console run six weeks behind has its priorities exactly backwards.

The questions to ask your IT provider this week

You do not need to be technical to hold your provider accountable. You need the right questions and a sense of what a good answer sounds like. Send these in an email so you get the answers in writing.

Question What a good answer looks like
Do you use N-able N-central anywhere in your stack? A direct yes or no. If yes: patched to Hotfix 2, IoC detection scripts run, results shared with you. If they cannot answer within a business day, that silence is an answer.
How do you manage the security of your remote management tools? A confident description of their process: patch timelines, access control, monitoring. They do not need to name products to prove they take it seriously, and a thoughtful provider may decline to name them for security reasons.
Who can access the console that controls our devices? A specific, small number of named roles, with least-privilege access and prompt removal when staff leave.
Is MFA enforced on that console? Yes, enforced for every account with no exceptions, ideally phishing-resistant MFA rather than SMS codes.
How quickly do you patch your own tools? A stated timeframe, such as 48 hours for actively exploited vulnerabilities. Bonus points if they patch their own systems faster than the contractual SLA they give you.
If your systems were breached, when and how would you tell us? A clear notification commitment, in writing, ideally already in your agreement. “That won’t happen to us” is a red flag, not reassurance.

We wrote a broader guide on MSP due diligence, contract clauses and red flags if you want to go deeper than this incident. The short version: a provider who welcomes these questions is a provider who has already asked them of themselves.

What this means if you manage IT in-house

The alert is addressed to MSPs and enterprise IT teams alike. If your internal team runs N-central, the ACSC’s guidance is blunt: upgrade to Hotfix 2 as a priority, run the vendor’s IoC detection scripts, monitor for suspicious activity, and report anything unusual to the ACSC on 1300 CYBER1.

And if your internal team runs any RMM, the same governance questions apply. Console access, enforced MFA, patch timelines for the management tooling itself. Internal IT does not get a pass on this because the attacker does not care who signs the administrator’s payslip.

What you should do now

Email your IT provider today and ask the N-central question. One line is enough: “Do you use N-able N-central, and if so, have you applied Hotfix 2 and run the IoC scripts?” The ACSC has told Australian businesses to ask. A good provider will answer the same day.

Get your provider’s tooling security posture in writing. Use the table above. The answers belong in your vendor file alongside your insurance documents, because your cyber insurer will ask about third-party access at claim time, and “we never asked” is an expensive answer.

Get an independent view of your exposure. If the answers you get back are vague, slow, or defensive, that tells you something important. Our managed cyber security team can run a security gap analysis that covers third-party and supply chain access, and we will happily be the second opinion on another provider’s homework. Contact us to set it up.

Frequently asked questions

What is the N-able N-central vulnerability?

The N-able N-central vulnerability alert covers two authentication bypass flaws, CVE-2026-18556 and CVE-2026-18577, both rated high severity at 8.2. They can allow attackers unauthorised access to the N-central RMM platform without valid credentials, and the ACSC has observed active exploitation in Australia.

Has the N-able N-central vulnerability been patched?

Yes. N-able released patches on 1 August 2026 and Hotfix 2 on 6 August 2026, and the ACSC advises upgrading to Hotfix 2 as a priority. Patching alone is not enough if exploitation happened first, so organisations should also run the vendor’s indicator of compromise detection scripts.

How do I know if my MSP uses N-central?

Ask them directly, in writing. The ACSC specifically advises small and medium businesses to engage with their MSP or IT provider to find out whether the N-able N-central product is in use. A provider who cannot or will not answer promptly is telling you something about how they run their operation.

What is an RMM tool and why does it matter?

A remote monitoring and management (RMM) tool is the platform an IT provider uses to monitor, patch, script and control every device it manages, with administrator rights. That concentration of access is what makes RMM platforms prime targets: compromising one console can expose every business behind it.

What should I do if my IT provider was breached?

Ask for the scope in writing, reset credentials the provider held or could access, check your own systems for unusual activity, and notify your cyber insurer early. Depending on what data was exposed, you may have obligations under the Privacy Act’s notifiable data breaches scheme, and the ACSC can assist on 1300 CYBER1.

Not sure what your IT provider’s tools expose you to?

Our Perth-based team will give you a straight answer. Book a free security gap analysis covering third-party and supply chain access today.

Book a Free Security Review

About the Author
Written by Greg Markowski, Founding Director of Epic IT, a CRN Fast50-recognised Microsoft Solutions Partner managing IT and cybersecurity for Perth businesses since 2003. Greg holds a Degree in Computer Science and a Diploma in Computer Systems Engineering from Edith Cowan University, and is ITIL certified.

Further Reading

Previous

GPT-6 Astra finds zero-days on its own. Here's what it means

Return to News
Back to News
Next

The Essential Eight is 126 of the ISM's 1,143 controls