Available 24/7 · Same-day on-site across Gloucestershire 01452 701355 sales@systemforce.co.uk Remote Help Network Status

N-able Attack: What UK Businesses Need to Ask Their MSP

If your business relies on an IT support provider, this story is worth a few minutes of your time even if you have never heard of N-able or N-central. Over the past fortnight, attackers exploited a serious vulnerability in one of the most widely used remote management platforms for IT firms, gaining access not just to the provider’s own systems, but in many cases to the business systems of every client on their books.

What is N-able N-central?

N-able N-central is a remote monitoring and management (RMM) platform used by thousands of managed IT support providers worldwide. RMM tools are what allow your IT provider to monitor your servers, push software updates, and fix problems without needing to visit your office. They are, in effect, the backbone of modern IT support. Without them, most outsourced IT firms could not operate at the scale they do.

What happened

On 31 July 2026, N-able began investigating reports of unusual activity on its N-central platform. The root cause was CVE-2026-18556: a critical authentication bypass vulnerability with a severity score of 8.2 out of 10. Authentication bypass means an attacker can skip the login process entirely and gain full administrative access to a platform without valid credentials. The front door, in effect, was wide open.

N-able released an emergency fix on 2 August. However, that first patch was incomplete. Researchers identified a residual bypass route, catalogued as CVE-2026-18577, which attackers were already exploiting before the second fix could be applied. A second hotfix (version 2026.3.1.10, released on 6 August) addressed both vulnerabilities with additional hardening measures and is required even for organisations that had already applied the first patch.

CISA, the US government’s cyber security agency, added both CVEs to its Known Exploited Vulnerabilities (KEV) catalogue in early August. The KEV catalogue is reserved for vulnerabilities confirmed to be actively used in real-world attacks, not theoretical risks.

How the attack played out

Once inside an N-central server, attackers had the same level of access as the IT provider’s own engineers. They then abused the platform’s built-in “Take Control” feature, a legitimate remote-access tool, to reach the managed endpoints of client businesses without triggering obvious alerts. Confirmed attack behaviour included deploying Cloudflare tunnels, a technique used to maintain persistent, hidden remote access, ensuring attackers could return even after the initial breach was closed.

The critical point: a single compromised RMM platform opened the door to potentially hundreds of individual businesses simultaneously. This is what security researchers call a supply chain attack, and it is one of the most effective tactics used by ransomware groups precisely because the leverage is so high.

Who was at risk?

All N-central installations prior to version 2026.3.1.7 were affected. N-able’s cloud-hosted N-central environments were patched automatically by the vendor. On-premise deployments required manual action. Confirmed compromises of MSP customers were reported while both vulnerabilities remained unpatched.

Why this matters even if your provider does not use N-central

The wider lesson from this incident is one that applies regardless of which RMM tool your IT provider uses: the security of your IT support partner is, in practice, part of your own security posture.

If your provider’s management tools are compromised, attackers gain a trusted path into your environment. That is true of N-central, and it is equally true of any other remote management platform. The question is not which tool your provider uses, but how they manage and protect it.

Questions worth raising with your IT provider

  • How do you keep your own management tools patched and updated? A good provider will have a clear, documented answer.
  • Do you hold independent security accreditation for your own operations? Certifications such as ISO/IEC 27001 require audited controls over the tools and processes an organisation uses internally.
  • What is your incident response plan if your own systems are affected? A reputable provider should be able to explain how they would detect, contain, and communicate such an event.

How System Force IT approaches its own security

System Force IT holds UKAS-accredited ISO/IEC 27001 certification. That means our own information security management, including the tools and platforms we use to manage client environments, is subject to independent annual audit. It is not a marketing badge; it is a structured commitment to maintaining and demonstrating security controls throughout our operation.

If the N-able incident has prompted questions about your current IT support arrangement, our IT security services page covers how we approach security for client environments. You can also read about the managed IT services we provide across Gloucestershire and the UK, including how we handle patching, monitoring, and incident response.

We are also strong advocates for Cyber Essentials certification for SMBs. It is not just about protecting your own systems; it signals to suppliers, insurers, and clients that you take security seriously.

If you would like to talk through any of this, get in touch or call us on 01452 701355 for a no-obligation conversation about how we work and what to look for in any IT support provider.

Stay one step ahead of the threats

Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.

Get the free weekly briefing →

Table of Contents

Would you like to know how we can help?

Get in touch

Name