Most UK small businesses don’t manage their own servers and laptops directly, they pay a managed service provider (MSP) to do it, using remote monitoring and management (RMM) software that gives that provider deep access to every connected machine. This week’s warning matters because one of the most widely used RMM platforms, N-able’s N-central, has a vulnerability under active exploitation right now, and researchers estimate over half of reachable cloud-hosted N-central servers remain unpatched.
The flaw, tracked as CVE-2026-18577, is an authentication bypass that survived an earlier attempted patch. It lets an attacker gain administrative control of the N-central console itself, meaning every client machine that MSP manages becomes reachable in one move. Security firm Huntress has already confirmed real-world compromise: attackers used one breached partner account to reach nine separate client organisations. CISA has added it to its Known Exploited Vulnerabilities catalogue, its clearest signal that this isn’t theoretical.
Why this is your problem, not just your IT provider’s
The uncomfortable truth about outsourcing IT support is that you inherit your provider’s security posture along with their expertise. If your MSP runs N-central and hasn’t patched it, an attacker who compromises their console can deploy scripts, open remote sessions, and move across your systems exactly as if they were your own IT administrator, because to the software, they are. This is the same “trusted vendor” pattern behind nearly every major supply-chain breach of the last few years: attackers no longer need to break into your business directly when breaking into the company you trust achieves the same result at scale.
What to actually ask your IT provider this week
Ask directly: “Do you use N-able N-central, and have you applied the August patches for CVE-2026-18576 and CVE-2026-18577?” A confident, specific answer is a good sign. Vagueness or a delayed response is not.
Ask what monitoring they have for unusual activity on their own management console, not just on your machines. The compromise happens one level up from where most businesses think to look, so your provider’s internal security matters as much as the tools they point at you.
Ask whether multi-factor authentication is enforced on every account with access to the RMM platform, including any subcontractors or third parties they use. Huntress’s findings show a single compromised login was enough to reach nine businesses; MFA is the cheapest control that would have blocked that path.
This is also a good moment to have a broader conversation with your provider, or with a firm like CoolCoding, about how your systems are actually configured and monitored day to day, rather than assuming “we have an IT company” is itself a security control.
The pattern worth remembering
RMM and MSP compromises aren’t rare, they’re a recurring category of attack precisely because they offer attackers a multiplier: one flaw, one breached login, dozens of downstream victims. Sectors already reported affected by this specific incident include education, financial services, local government, healthcare, and manufacturing, a genuine cross-section of the kind of organisations that outsource IT rather than run it in-house. If you’ve never asked your provider what software sits between them and your systems, this is a reasonable week to start.
The takeaway
You can’t audit your IT provider’s entire stack, but you can ask one specific, informed question and see how confidently it’s answered. A provider that already knows about N-central’s August vulnerabilities and has patched them is doing its job. One that doesn’t know what you’re asking about is worth a harder look, ideally with independent monitoring such as KeepSafe watching for signs of compromise that neither of you has spotted yet.