# The Keys to Hundreds of Networks: Attackers Are Actively Exploiting a Patched N-able RMM Flaw That Wasn't Actually Patched
Threat actors are exploiting a patch bypass vulnerability in N-able's remote monitoring and management platform, turning the software that managed service providers use to protect their clients into an entry point for attacking them all at once.
RMM compromises are not ordinary endpoint breaches. They're supply chain attacks in slow motion.
## What "Patch Bypass" Actually Means for Defenders
A patch bypass is worse than a new zero-day in one specific way: it burns trust. Organizations that applied N-able's original fix — doing exactly what they were supposed to do — were left believing they were protected when they weren't. The flaw wasn't remediated; it was rerouted around.
N-able, formerly SolarWinds MSP before a 2021 spin-off designed partly to distance from that brand's catastrophic baggage, provides RMM software used by thousands of MSPs worldwide. Those MSPs in turn manage endpoints for tens of thousands of small and mid-sized businesses. When an attacker compromises the RMM server itself — not a client endpoint, not a workstation, but the management plane — they don't need to breach each customer individually. They inherit the access the MSP already has.
The specific vulnerability details that have emerged indicate the bypass allows unauthenticated or low-privilege attackers to escalate against N-able's N-central platform, potentially enabling remote code execution on RMM infrastructure. Exploitation has been observed in the wild, meaning this moved from theoretical to operational — and the window between patch publication and active exploitation compressed to essentially nothing.
## A Pattern MSPs Should Have Memorized by Now
The targeting of RMM infrastructure isn't new. It has a documented, ugly history:
N-able now joins a list that every MSP should have framed on the wall. The attack surface is structural, not incidental. MSPs hold privileged access to client networks as a feature — and that feature is exactly what attackers want.
## Who Gets Burned When an RMM Goes Down
The blast radius here is worth spelling out concretely, because it rarely gets emphasized enough in vendor advisories.
A compromised N-able RMM server gives an attacker:
MSPs serving SMBs are a particularly high-return target because their clients typically lack dedicated security staff. A ransomware operator who drops payloads on 200 endpoints across 40 small businesses through a single MSP compromise has done the work of 40 separate intrusions in one move.
## What Defenders Need to Do Right Now
If your organization uses N-able N-central, or if you're a client of an MSP that does, the immediate priorities are clear:
For MSPs:
For MSP clients:
The Cybersecurity and Infrastructure Security Agency's guidance on RMM security (available at cisa.gov) remains the clearest framework for hardening these environments.
---
## HackWire Analysis
The N-able patch bypass lands in a moment when the managed service provider ecosystem is under more regulatory and customer scrutiny than ever — and still not changing fast enough.
What's missing from most coverage of this incident is the meta-problem: patch bypass vulnerabilities specifically expose the false confidence that patch compliance creates. Security teams measure patch velocity as a KPI. Executive reports show "98% of critical patches applied within 72 hours." And yet, if the patch itself is incomplete, that entire compliance apparatus becomes a liability — it tells leadership that risks are managed when they aren't.
N-able's origin story compounds this. The SolarWinds 2020 supply chain attack — where Russia's SVR embedded malicious code into SolarWinds Orion updates that then propagated to 18,000 customers including multiple U.S. federal agencies — is the defining case study in this threat category. N-able was spun out from SolarWinds MSP in early 2021, partly as a business restructuring and partly as a branding exercise. The underlying mission hasn't changed: run the management infrastructure that MSPs depend on. Neither has the threat.
The pattern across Kaseya, ConnectWise, and now N-able is consistent enough that "RMM exploitation" should be treated as a standing threat category requiring dedicated controls — network segmentation of RMM infrastructure, continuous behavioral monitoring of RMM agent processes, and explicit contractual language in MSP agreements requiring security attestations. The clients who are going to get hurt in this wave are the ones who never thought to ask their MSP what RMM software they use.
The ransomware groups targeting MSP infrastructure are not unsophisticated. They are patient, well-resourced, and acutely aware that one successful compromise multiplies into dozens of paydays. Until the industry treats RMM security with the same rigor it applies to, say, firewall configuration, this story will repeat.
— HackWire Editorial
---
## Related Coverage