On 19 August, the ACSC sent out a high alert marked “act quickly”. Attackers are actively exploiting two vulnerabilities in N-able N-central, a remote monitoring and management platform, and they are doing it here in Australia. If you have never heard of N-central, that is exactly the problem. Your IT provider probably has, because tools like it are how MSPs manage your entire business.
This is the alert we have been telling clients to expect. Attackers stopped kicking down individual front doors years ago. Breaching one MSP’s management console opens every client behind it, and the N-able N-central vulnerability alert is the clearest local proof yet that criminals know it.
The ACSC alert names two flaws: CVE-2026-18556 and CVE-2026-18577. Both are authentication bypass vulnerabilities scored 8.2 (high severity), and both may allow unauthorised access through an alternate path or channel. In plain English: a way in that does not require anyone’s password.
The vulnerabilities affect all current versions of N-central, including 2026.3. N-able released patches on 1 August and a follow-up Hotfix 2 on 6 August, and the ACSC says organisations should upgrade to Hotfix 2 as a priority. The vendor has also published indicator of compromise detection scripts, which matters because patching closes the door but does not evict anyone who already walked through it.
Two details in the alert deserve your attention. First, the ACSC has observed active exploitation within Australia. This is not a theoretical advisory about something happening overseas. Second, the ACSC explicitly advises that small and medium businesses should ask their MSP whether they use the product. The government is telling you, the business owner, to question your IT provider. We think you should take them up on it.
A remote monitoring and management platform is the tool an IT provider uses to see and control every device it manages. Deploy software to 500 machines at once. Run scripts with administrator rights. Reset passwords. Disable security tools. Push updates. All from one console.
That is precisely what makes an RMM the highest-value target in the managed services world. An attacker who compromises a single business gets one business. An attacker who compromises an MSP’s RMM console gets every client that MSP manages, with legitimate administrator access that endpoint detection and response tools are configured to trust. The malicious activity arrives through the same channel your normal IT support does.
There is something genuinely uncomfortable about this for our industry. The tools that make managed IT affordable are the same tools that concentrate risk. Any MSP that pretends otherwise is not being straight with you.
In July 2021, the REvil ransomware group exploited Kaseya VSA, another RMM platform, and used it to push ransomware through roughly 60 MSPs to as many as 1,500 downstream businesses in a single weekend. Most of those businesses had never heard of Kaseya. They were encrypted anyway, because their IT provider’s tooling was the delivery mechanism.
Since then, RMM and remote access tools have been hit repeatedly, and intelligence agencies across the Five Eyes have warned that state and criminal actors deliberately target MSPs to reach their clients. The N-central campaign is not an anomaly. It is the current instalment of a pattern that is now five years old and getting worse, for a simple reason: it works.
Full disclosure: Epic IT does not use N-able N-central, so our clients are not exposed to these specific CVEs through us.
We are not going to gloat about that, because it would be dishonest. Every MSP runs remote management tooling of some kind, us included, and every one of those platforms is a high-value target. The difference between a safe provider and a dangerous one is not which product they bought. It is how seriously they treat their own attack surface. We deliberately do not publish which platforms we run, for the same reason you would not publish a map of your office keys.
When the ACSC alert landed, our response was not relief. It was a prompt to re-check our own house: confirm our tooling is current, review who holds console access, verify phishing-resistant MFA is enforced on every administrative account, and check our vendors’ security advisories for anything similar brewing. We hold our own tooling to the same Essential Eight patching timelines we implement for clients, because an MSP that patches client systems within 48 hours but lets its own console run six weeks behind has its priorities exactly backwards.
You do not need to be technical to hold your provider accountable. You need the right questions and a sense of what a good answer sounds like. Send these in an email so you get the answers in writing.
| Question | What a good answer looks like |
|---|---|
| Do you use N-able N-central anywhere in your stack? | A direct yes or no. If yes: patched to Hotfix 2, IoC detection scripts run, results shared with you. If they cannot answer within a business day, that silence is an answer. |
| How do you manage the security of your remote management tools? | A confident description of their process: patch timelines, access control, monitoring. They do not need to name products to prove they take it seriously, and a thoughtful provider may decline to name them for security reasons. |
| Who can access the console that controls our devices? | A specific, small number of named roles, with least-privilege access and prompt removal when staff leave. |
| Is MFA enforced on that console? | Yes, enforced for every account with no exceptions, ideally phishing-resistant MFA rather than SMS codes. |
| How quickly do you patch your own tools? | A stated timeframe, such as 48 hours for actively exploited vulnerabilities. Bonus points if they patch their own systems faster than the contractual SLA they give you. |
| If your systems were breached, when and how would you tell us? | A clear notification commitment, in writing, ideally already in your agreement. “That won’t happen to us” is a red flag, not reassurance. |
We wrote a broader guide on MSP due diligence, contract clauses and red flags if you want to go deeper than this incident. The short version: a provider who welcomes these questions is a provider who has already asked them of themselves.
The alert is addressed to MSPs and enterprise IT teams alike. If your internal team runs N-central, the ACSC’s guidance is blunt: upgrade to Hotfix 2 as a priority, run the vendor’s IoC detection scripts, monitor for suspicious activity, and report anything unusual to the ACSC on 1300 CYBER1.
And if your internal team runs any RMM, the same governance questions apply. Console access, enforced MFA, patch timelines for the management tooling itself. Internal IT does not get a pass on this because the attacker does not care who signs the administrator’s payslip.
Email your IT provider today and ask the N-central question. One line is enough: “Do you use N-able N-central, and if so, have you applied Hotfix 2 and run the IoC scripts?” The ACSC has told Australian businesses to ask. A good provider will answer the same day.
Get your provider’s tooling security posture in writing. Use the table above. The answers belong in your vendor file alongside your insurance documents, because your cyber insurer will ask about third-party access at claim time, and “we never asked” is an expensive answer.
Get an independent view of your exposure. If the answers you get back are vague, slow, or defensive, that tells you something important. Our managed cyber security team can run a security gap analysis that covers third-party and supply chain access, and we will happily be the second opinion on another provider’s homework. Contact us to set it up.
The N-able N-central vulnerability alert covers two authentication bypass flaws, CVE-2026-18556 and CVE-2026-18577, both rated high severity at 8.2. They can allow attackers unauthorised access to the N-central RMM platform without valid credentials, and the ACSC has observed active exploitation in Australia.
Yes. N-able released patches on 1 August 2026 and Hotfix 2 on 6 August 2026, and the ACSC advises upgrading to Hotfix 2 as a priority. Patching alone is not enough if exploitation happened first, so organisations should also run the vendor’s indicator of compromise detection scripts.
Ask them directly, in writing. The ACSC specifically advises small and medium businesses to engage with their MSP or IT provider to find out whether the N-able N-central product is in use. A provider who cannot or will not answer promptly is telling you something about how they run their operation.
A remote monitoring and management (RMM) tool is the platform an IT provider uses to monitor, patch, script and control every device it manages, with administrator rights. That concentration of access is what makes RMM platforms prime targets: compromising one console can expose every business behind it.
Ask for the scope in writing, reset credentials the provider held or could access, check your own systems for unusual activity, and notify your cyber insurer early. Depending on what data was exposed, you may have obligations under the Privacy Act’s notifiable data breaches scheme, and the ACSC can assist on 1300 CYBER1.