N-central is not a product most employees have heard of, and that is exactly the problem. It is the remote monitoring and management platform that managed service providers use to patch, monitor, and remotely access servers and endpoints across every client they serve, from a single console. When that console has an authentication bypass, the blast radius is not one company. It is every business that trusted an MSP to look after their infrastructure, a group that includes a large share of the small and mid-sized organisations across Europe who outsource IT precisely so they do not have to think about this.
A fix that fixed the wrong path
N-able first addressed the flaw in version 2026.2, believing it had closed the authentication bypass. It had not. Attackers found an alternate route to the same unauthenticated, administrative-level access, tracked as CVE-2026-18556 and CVE-2026-18577, and used it to take over N-central servers regardless of the earlier patch. On August 2, N-able shipped hotfix 2026.3.1.7 as the first build that actually closes both paths, and it is now urging every customer, hosted or on-premises, to upgrade immediately rather than wait for a routine maintenance window.
Why this one is worse than a typical console breach
Gaining admin access to N-central was only the opening move. Once inside, attackers used the platform’s own Take Control feature, the legitimate remote-access tool MSPs rely on to reach client machines, to pivot into managed endpoints and register Cloudflare Tunnels as persistent services on them. Because those tunnels connect outward to Cloudflare’s edge, they need no inbound firewall rule and no open listening port, which makes them close to invisible to conventional network monitoring. Running them as a service means they survive a reboot, and N-able has confirmed the access persisted even after the compromised route through N-central itself was cut off. Organisations checking their exposure should look for a file named svchost.exe sitting in a user’s Documents folder and a registered service called Cloudflared, both signs the tunnel was already planted before anyone patched.
The MSP model concentrates the risk this time
The value of centralised remote management is also its liability: one compromised console can reach dozens or hundreds of downstream networks that never chose N-central themselves, because their MSP did. For European businesses that lean on managed providers to stay compliant with NIS2 and DORA obligations around third-party risk, this incident is a live example of exactly the scenario those frameworks ask you to plan for. A vendor’s software is part of your attack surface whether or not you evaluated it directly, and “our MSP patches things for us” is not a substitute for confirming they actually did, on this specific advisory, this week.
If your organisation relies on a managed service provider and you want an independent check on whether your endpoints show signs of this compromise, or you need help building third-party risk oversight that goes beyond trusting a vendor’s patch notes, contact Excello Digital. We help European businesses verify their supply chain security instead of assuming it.
