preloader

· digital-security devops msp supply-chain vulnerability-management patch-management cve europe rmm incident-response

N-able’s First Fix Didn’t Work. Attackers Are Now Living Inside MSP Networks Through Cloudflare Tunnels

Source: The Hacker News

N-central is not a product most employees have heard of, and that is exactly the problem. It is the remote monitoring and management platform that managed service providers use to patch, monitor, and remotely access servers and endpoints across every client they serve, from a single console. When that console has an authentication bypass, the blast radius is not one company. It is every business that trusted an MSP to look after their infrastructure, a group that includes a large share of the small and mid-sized organisations across Europe who outsource IT precisely so they do not have to think about this.

A fix that fixed the wrong path

N-able first addressed the flaw in version 2026.2, believing it had closed the authentication bypass. It had not. Attackers found an alternate route to the same unauthenticated, administrative-level access, tracked as CVE-2026-18556 and CVE-2026-18577, and used it to take over N-central servers regardless of the earlier patch. On August 2, N-able shipped hotfix 2026.3.1.7 as the first build that actually closes both paths, and it is now urging every customer, hosted or on-premises, to upgrade immediately rather than wait for a routine maintenance window.

Why this one is worse than a typical console breach

Gaining admin access to N-central was only the opening move. Once inside, attackers used the platform’s own Take Control feature, the legitimate remote-access tool MSPs rely on to reach client machines, to pivot into managed endpoints and register Cloudflare Tunnels as persistent services on them. Because those tunnels connect outward to Cloudflare’s edge, they need no inbound firewall rule and no open listening port, which makes them close to invisible to conventional network monitoring. Running them as a service means they survive a reboot, and N-able has confirmed the access persisted even after the compromised route through N-central itself was cut off. Organisations checking their exposure should look for a file named svchost.exe sitting in a user’s Documents folder and a registered service called Cloudflared, both signs the tunnel was already planted before anyone patched.

The MSP model concentrates the risk this time

The value of centralised remote management is also its liability: one compromised console can reach dozens or hundreds of downstream networks that never chose N-central themselves, because their MSP did. For European businesses that lean on managed providers to stay compliant with NIS2 and DORA obligations around third-party risk, this incident is a live example of exactly the scenario those frameworks ask you to plan for. A vendor’s software is part of your attack surface whether or not you evaluated it directly, and “our MSP patches things for us” is not a substitute for confirming they actually did, on this specific advisory, this week.

If your organisation relies on a managed service provider and you want an independent check on whether your endpoints show signs of this compromise, or you need help building third-party risk oversight that goes beyond trusting a vendor’s patch notes, contact Excello Digital. We help European businesses verify their supply chain security instead of assuming it.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!