decrypted · 8 september 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain
N-able's fourth patch in five weeks exposes the risk in remote monitoring tools
When N-able shipped its fourth hotfix in five weeks for the same platform on 6 September, it wasn't patching four unrelated bugs. It was chasing a pattern. The latest, CVE-2026-86218, is a maximum severity, CVSS 10.0, pre-authentication remote code execution flaw in N-central, the remote monitoring and management tool that managed service providers use to run their clients' IT, UK ones included. N-able's public advisory says it has "no confirmations" the flaw has been exploited in production. A notice sent directly to customers says the opposite: that it "has been observed being exploited in the wild." Both statements came from the same vendor, about the same bug, in the same week.
One console, every client
An RMM platform is the master keyring for an IT estate. It holds credentials, pushes commands to every managed device, and talks to client networks over a channel those networks are configured to trust implicitly. Get code execution on the N-central server itself, as this flaw allows without so much as a login, and you don't just own N-able's box. You own the keyring: stored credentials, configuration for every managed network, and a legitimate channel to issue commands to any endpoint N-central watches over. Huntress, the security firm that spotted attackers probing N-central's getPierDetails endpoint and quietly renaming accounts with .invalid suffixes, found a fully patched customer environment already compromised on 4 September, two days before this latest fix existed. The Shadowserver Foundation counts nearly 1,500 internet-exposed N-central servers, concentrated in the US and Europe.
The pattern is the actual lesson
This is the third distinct vulnerability chain in N-central since early August: an authentication bypass, a follow-up bypass pair, now a pre-auth RCE rated the maximum possible severity. That frequency says more than any single CVE does. A tool built to hold this much trust over this many downstream networks needed to be designed so that a compromise of the console couldn't cascade outward by default: segmented management interfaces, no direct internet exposure, tight input validation on every endpoint reachable pre-authentication. Four hotfixes in five weeks reads like a vendor firefighting an architecture problem one report at a time, not isolated bad luck.
For UK organisations, the actionable point isn't "patch your RMM tool", most won't run it directly. It's that outsourcing IT to an MSP means inheriting the MSP's attack surface as your own. Ask whether your provider runs N-central on-premises or hosted, whether Hotfix 4 (build 2026.3.1.14) is applied, and whether the management console is reachable from the open internet at all. Supply chain risk assessments that stop at software vendors and skip the MSP holding the keys to your endpoints are missing the part most likely to hurt.
Also this week
A poisoned registry, not a poisoned package. Coder, a platform used by government and private organisations to run self-hosted developer environments, had its Cloudflare infrastructure compromised between 07:35 and 21:45 UTC on 31 August. Attackers inserted their own IP addresses into the pool behind registry.coder.com, so the legitimate domain intermittently served malicious Terraform modules built to harvest cloud API keys, CI/CD credentials, SSH keys and OIDC tokens. Coder rates the incident 9.0 of 10 and admits it cannot identify every affected deployment, because the attacker's infrastructure sits outside its control. The lesson is the same one xz-utils taught: verifying a domain isn't verifying its contents when the infrastructure serving that domain is what's compromised.
A leak site listing, not a confirmed breach. The Qilin ransomware group added The Big Table, the UK hospitality group behind Bella Italia, Café Rouge and Frankie & Benny's, to its leak site on 5 September. The post carries no description and no sample data, and neither The Big Table nor Qilin has published anything to substantiate it. Worth noting as a claim, not yet worth treating as fact.
Sources
- N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) - Help Net Security
- Critical N-able N-central Vulnerability and Active Exploitation - Huntress
- N-able Releases Hotfix for Critical Remote Code Execution Flaw - Infosecurity Magazine
- Coder platform targeted by attackers delivering malicious Terraform modules - SC Media
- Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules
- Victim: The Big Table – Qilin - ransomware.live
If any of this touches your own vendor or supply chain risk, get in touch.
More like this
- The SSO flaw that let one attacker log in as 138 companies 11 september 2026
- The espionage group that taught routers to hide their own tracks 1 september 2026
- The NCSC's third warning in five months about exposed edge devices 30 august 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.