DECRYPTED_LOG[2026.08.13]

Two Hotfixes In, and Most IT Managers Still Can't Name the Tool With Admin Rights Into Their Estate

Cover Image for Two Hotfixes In, and Most IT Managers Still Can't Name the Tool With Admin Rights Into Their Estate

Ask an IT manager to list everything with standing admin rights into their environment. You'll get domain admins, the cloud platform team, maybe the SOC if there's a proper one. Almost nobody gets to the tool their MSP uses to patch, monitor, and remote into every endpoint they touch. That one's usually just assumed. Someone else's problem, someone else's login.

On July 31, Adlumin's MDR team caught something odd inside a customer environment running N-central, the RMM platform a lot of MSPs use to run their client networks from one console. What they'd found was a fresh authentication bypass, CVE-2026-18577, CVSS 8.2, that skips the login screen entirely and drops an attacker straight into console admin. N-central ships with a "Take Control" feature built for technicians to jump into managed endpoints. An attacker with admin on the console doesn't need to touch those endpoints one by one. They're already through the door the technicians use.

N-able shipped a hotfix on August 2. It didn't hold. Attackers kept exploiting the flaw through it, and a second hotfix landed August 6 before N-able would call it actually closed. CISA had the vulnerability on its Known Exploited Vulnerabilities catalog by August 3 and gave US federal agencies until August 6, a three-day window, to patch. Federal timelines like that are reserved for the ones already being used against real targets.

At least one victim got hit at roughly 08:00 UTC on August 3. The attacker rode the compromised N-central server into a backup server, domain controllers, application servers, then registered outbound Cloudflare tunnels as Windows services so they'd still have a way in once the obvious stuff got cleaned up. Setting up a tunnel that quietly phones home isn't opportunistic. Someone planned to be back.

None of that is really an N-able story, though. N-central is available to MSPs here and across the Tasman, and if your organisation runs IT through a managed provider, which a fair chunk of mid-market NZ does, there's a decent chance something exactly like it sits between your MSP and every machine you own. Not through negligence. Through the actual design of an RMM platform. One console, one login, reaching everything, so the MSP doesn't need forty separate credentials to keep your lights on.

Good trade, most days. Two weeks ago it meant one auth bypass put every managed endpoint downstream in play at the same time, no lateral movement required, no phishing email, nothing your own security awareness training would have caught. Your firewall didn't fail. Someone else's admin console did, and your firewall was never in the conversation.

Most IT managers genuinely wouldn't know if that happened to them. Not the CVE number, the basic version. Whether their MSP even runs N-central, or something like it. Whether the contract says "we'll tell you within 24 hours" or just doesn't say anything. Ask around and it's mostly the second one.

You don't need to run your MSP's patch cycle. Nobody's asking for that. Knowing what has standing access into your estate, and how fast you'd hear about it going sideways, is a different bar. Worth checking where yours actually sits before something answers the question for you.