Filed under: Cybersecurity — Patching & Vendor Risk — August 2026

What happened

N-able, maker of the N-central platform that thousands of IT service providers use to remotely monitor and fix client computers, disclosed that attackers broke into N-central servers using a login bypass that let them get administrator access without a password (CVE-2026-18556). N-able’s first patch didn’t fully close the hole — a second exploitation path (CVE-2026-18577) was found days later — so it rushed out an emergency fix, build 2026.3.1.7, on August 2. Once inside a server, attackers used its built-in remote-control feature to reach the computers that server manages, then planted a hidden backdoor designed to survive a reboot and outlast the patch.

Why it matters to your business

If your business relies on an outside IT company for support rather than an in-house team, there’s a good chance they use a remote monitoring and management tool like this one to patch and troubleshoot your machines without a truck roll. That’s exactly what makes this software such a valuable target: one compromised management server can hand attackers a foothold into every client network it touches, including yours, through no fault of your own. It’s the same style of attack that hit small businesses through their IT providers in the 2021 Kaseya ransomware incident.

What to do this week

Ask your IT provider directly: “Do you use N-able N-central, and if so, have you upgraded to build 2026.3.1.7 or later?” Being on 2026.2 is not enough — that version was still exposed to the second bug. Ask whether they’ve checked managed devices for a service named “Cloudflared” or a stray svchost.exe sitting in a Users\Documents folder, both signs of the backdoor attackers left behind, since patching the server alone doesn’t remove access already planted on endpoints. If you run N-central yourself in-house, upgrade immediately and review ui_access_control.log and the BASupSrvc logs for Take Control sessions you don’t recognize.

The bigger picture

Your security is only as strong as the tools your IT vendor relies on, and a vendor that patches fast and checks for leftover backdoors — not just the version number — is doing the job right. Proactive vs. Reactive IT Management: Lessons from Healthcare for SMBs

Not sure what remote-management tools are touching your network, or who’s watching them? Book a free consult — https://micro1tech.com/contact/