When a vendor flaw lets attackers into your business – what you must do now

When a vendor flaw lets attackers into your business – what you must do now
Sub‑headline: Attackers exploited a remote‑monitoring tool. Here’s how to protect your data today.
A critical vendor flaw in a popular remote‑monitoring platform gave attackers administrative control over the tool and a path into the networks of its customers. If you rely on any remote‑monitoring or management (RMM) solution, the steps below will help you stop the current attack and reduce the chance of a similar incident tomorrow.
What the vendor flaw (CVE‑2026‑18577) means for your business
N‑able, the maker of the N‑central RMM platform, confirmed that a zero‑day vulnerability (CVE‑2026‑18577) allowed an unauthenticated attacker to obtain full administrative rights on the management server. In plain language, an attacker could log in without a password and act as if they were the system’s owner.
Once inside, the attackers used the platform’s Take Control feature – a built‑in remote‑desktop function – to open sessions on the devices that the RMM tool was managing for its customers. To keep their foothold even after the compromised N‑central server was rebooted, they created a Cloudflare Tunnel (a secure tunnel that forwards traffic from the internet to a private machine). This gave them persistent, hidden access to the downstream systems.
N‑able released two mandatory hot‑fixes in quick succession. Hotfix 1 (released 2 August) addressed the initial flaw; Hotfix 2 (released 7 August) adds further hardening and is required even if you have already applied the first fix. The vendor says a “limited number” of customers were affected, but does not disclose exact figures.
Immediate remediation steps for business owners
Step 1: Verify you’ve applied the vendor‑flaw hot‑fixes
-
Run the vendor‑provided IOC scan
- N‑able published a list of ten IP addresses and a Windows‑endpoint detection template. Run the scan on all managed devices. Remember that a clean scan only means no known indicators were found; new indicators may appear later.
-
Reset all privileged credentials
- Change passwords and, where possible, enable two‑factor authentication (2FA) for any accounts that can access the RMM console. 2FA adds an extra step, like a code sent to a phone, making it harder for attackers to reuse stolen credentials.
-
Review and tighten remote‑control settings
- Disable any unused remote‑control features. Limit the “Take Control” function to a whitelist of trusted administrators and require explicit approval for each session.
-
Audit network traffic for unexpected tunnels
- Look for outbound connections to Cloudflare domains that you did not create. Unauthorised tunnels often show up as continuous traffic to
*.cloudflare.comfrom servers that should not be reaching the internet directly.
- Look for outbound connections to Cloudflare domains that you did not create. Unauthorised tunnels often show up as continuous traffic to
-
Consider a managed security service
- Continuous monitoring can spot suspicious activity that a one‑time scan misses. A dedicated security team can also handle patch management across all your tools, ensuring nothing slips through the cracks.
The broader lesson: any remote‑monitoring tool can become a backdoor
RMM platforms are valuable because they let IT staff manage dozens or hundreds of computers from a single console. That convenience also makes them attractive to attackers: compromising the console gives them a “master key” to every device the tool controls. Any vendor flaw in remote‑monitoring tools can become a backdoor that lets attackers move laterally across your network.
If you use any remote‑monitoring, backup, or automation service—whether it’s N‑central, a different RMM vendor, or a cloud‑based backup agent—the same risk applies. The key take‑aways are:
- Patch immediately when a vendor releases a security update. Delays give attackers a larger window to exploit the flaw.
- Verify the patch worked by checking version numbers and running any supplied detection tools.
- Maintain visibility with continuous monitoring or a managed security service that can alert you to abnormal behaviour in real time.
FAQ – vendor flaw remediation questions
Q: I don’t use N‑central. Do I still need to worry?
A: Yes. The underlying issue is the same for any remote‑monitoring platform that offers administrative access over the internet. Check with your vendor for any recent security advisories and apply patches without delay.
Q: My IT staff says they already applied Hotfix 1. Is that enough?
A: No. Hotfix 2 contains additional hardening that addresses techniques attackers used to bypass the first fix. Install the latest version even if you applied the earlier one.
Q: How can I tell if an attacker is still inside my network?
A: Look for unknown remote‑control sessions, unexpected outbound tunnels (especially to Cloudflare), and any of the published IP addresses. A managed security service can provide continuous threat hunting to catch hidden footholds.
Keep your business safe with proactive security
A vulnerability in a single tool can open the door to many of your critical systems. If you’re worried about a vendor flaw in your remote‑monitoring software, our Security & Protection service can keep you safe.
If you’re using remote‑monitoring software or want a safety net against future vendor flaws, get in touch with IT Move NL. Our Security & Protection service handles patch management, 24/7 threat monitoring and rapid incident response, so you can focus on running your bakery, clinic, or shop.
Sources:

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent
Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.
STAY IN THE LOOP
// Cloud, AI & DevOps insights — straight to your inbox.
No spam. Unsubscribe anytime.
// Related articles
Need help with your cloud infrastructure?
Our team of experts is ready to help you navigate the complexities of modern cloud architecture.
Get in Touch

