# N-able's N-Central RMM Hit With Max-Severity RCE — MSPs Are the Target, Their Clients Are the Victim
The vulnerability isn't the story. The blast radius is.
When a remote monitoring and management platform goes down with a CVSS 10.0 remote code execution flaw — the highest score the scale allows — the math gets ugly fast. N-central isn't just software running on one company's servers. It's the console that thousands of managed service providers use to administer endpoints across hundreds of their clients simultaneously. Compromise one N-central instance and you don't get one network. You get a passkey to dozens.
N-able confirmed the emergency hotfix on Friday, patching a critical unauthenticated RCE vulnerability in N-central with attacks already underway. The company didn't disclose the full technical details of the exploit chain, but "maximum severity" combined with "ongoing attacks" tells you everything that matters operationally: patch windows are already closed for some victims.
## The Platform That Manages Everything
MSPs live and die by their RMM stack. N-central is one of the market leaders — it sits on servers with administrative credentials to client environments, often with broad network access, the ability to push software, and elevated privileges on Windows domains. For an attacker, it's the master key.
That's exactly why threat actors have systematically targeted RMM platforms over the past five years. Kaseya's VSA platform was the delivery mechanism for the REvil ransomware campaign in July 2021, which hit roughly 1,500 downstream businesses through a single attack on one vendor. ConnectWise ScreenConnect suffered a critical authentication bypass in February 2024 that was exploited within 48 hours of public disclosure. Datto, TeamViewer, AnyDesk — the list of RMM vendors that have faced active exploitation keeps growing.
N-central fits the pattern. But there's an additional layer of history here that deserves attention.
## The SolarWinds Shadow
N-able is a SolarWinds spinoff. The company was divested in 2021, two years after the Orion supply chain attack — the most consequential intrusion in the history of enterprise software — but N-able carries institutional DNA from an organization that was already under the microscope for security practices. To be clear: N-able is a separate company, and this vulnerability has nothing to do with the 2020 SolarWinds incident. But the optics of a max-severity RCE actively under attack hitting an MSP platform with that lineage aren't lost on the security community watching this space.
What it does underscore is that RMM vendors as a category have become Tier 1 targets for ransomware operators and state-sponsored groups alike. The access they provide is simply too valuable.
## What "Ongoing Attacks" Actually Means for Your Clients
Emergency patches with active exploitation notices collapse the usual window defenders expect. Normal patch cycles assume you have days or weeks to test, deploy, and verify. Active exploitation strips that to hours — and in many cases, by the time vendors confirm attacks in progress, a subset of customers have already been hit.
For MSPs running N-central, the immediate action is obvious: apply the hotfix and verify the update propagated correctly across all N-central instances. What's less obvious is the post-patch triage. If an attacker had an exploit for this in the wild before the patch dropped, the question isn't just "did we patch?" — it's "were we compromised before we patched?"
That means:
---
## HackWire Analysis
The vulnerability itself — a max-severity RCE in an RMM platform — is serious. But the recurring pattern it represents is the more urgent story.
Defenders and executives in the MSP space have heard the CISA advisories about RMM targeting for years. The 2023 CISA advisory explicitly warned that malicious actors were using legitimate RMM software as an attack vector, highlighting how these tools evade endpoint detection because they're expected to have broad system access. That warning didn't stop the ConnectWise exploitation in 2024. This N-central incident suggests it hasn't stopped anything since.
What's missing from most coverage of these incidents is the downstream victim count. When Kaseya was hit in 2021, Huntress Labs estimated 1,500 to 2,000 businesses affected. When ConnectWise fell in 2024, CISA and FBI issued a joint advisory because the scale of exploitation was broad enough to warrant federal intervention. The N-able hotfix notice mentions "ongoing attacks" — which means that number is being assembled right now, and it won't be published alongside today's patch announcement.
The harder conversation is structural: MSPs are small businesses providing enterprise-grade access to their clients' environments. Their security budgets don't match the access they hold, and the economics of MSP work often mean patch windows get deferred. Attackers know this. They've built entire operational playbooks around it.
Any organization that outsources IT management to an MSP should be asking their provider — today — whether they run N-central, whether the hotfix has been applied, and whether they've run a compromise assessment. That question isn't optional anymore. It's due diligence.
— HackWire Editorial
---
## Related Coverage