Your IT provider's remote access is the way in

· · Security

Whoever looks after your computers, an outside IT company or a person in-house, almost certainly has software installed on every machine that lets them take control of it remotely. That is how support works. Somebody clicks something in a console and your laptop does what they tell it, without anyone walking to your desk.

Now ask the uncomfortable question. What happens if somebody else gets into that console?

What happened

N-able makes N-central, one of the platforms IT providers use to manage their customers' computers. On 31 July the company started investigating after on-premises customers produced an unusual volume of licensing errors. It found an attacker had gained remote administrative access to N-central servers.

From there, the attackers used N-central's own Take Control feature, the thing that exists to let a technician operate your machine, to reach the endpoints managed through those servers. This is documented in N-able's disclosure and reported alongside it.

Two vulnerabilities are involved, each scored 8.2. The first, CVE-2026-18556, is described in N-able's own record as "unauthenticated administrative account takeover". N-able fixed that path in build 2026.2. It then discovered a different way to exploit the same underlying weakness that the first fix did not block. That became CVE-2026-18577, and it moved the affected range to everything before build 2026.3.1.7, which shipped on 2 August. Finland's national security centre said in a 2 August advisory that all versions available before the emergency hotfix were vulnerable.

The first fix was not enough. That matters for what you ask next.

The part that outlives the patch

Once on a managed machine, the attackers registered Cloudflare tunnels as services.

A tunnel like this makes an outbound connection from the machine to an external service, then accepts instructions back down that same connection. Because the machine dials out, there is no inbound firewall rule to spot and no listening port sitting open for a scanner to find. Registering it as a service means it starts again after a reboot.

The consequence is the important bit. N-able says the tunnels preserved access after the route through the N-central server was revoked. Patching the platform closed the front door. It did nothing about the extra door installed on your machines while the front door was open.

Nothing here suggests Cloudflare was compromised. The attackers used a legitimate service the way anyone can.

What to ask your IT provider

You do not need to understand the vulnerability to have this conversation. Four questions, in this order:

"Do you use N-able N-central, and if so are you on 2026.3.1.7?" Not 2026.3, which was the original instruction and is no longer sufficient. If they host it themselves they must upgrade it; hosted instances are being upgraded on N-able's own schedule.

"Were we in the affected group?" N-able says it identified and contacted a limited number of affected customers but has not published a figure. Your provider either was contacted or was not, and either answer is useful.

"Have you hunted for tunnel services on our machines, not just patched the server?" This is the question that separates a real answer from a reassuring one. Upgrading N-central does not remove persistence installed on a different computer. N-able has published six IP addresses seen in the attacks, and the security firm Huntress identified four of them as Mullvad or NordVPN exit nodes, so a provider doing this properly is correlating those against their own logs rather than assuming.

"What would you have to tell us if this happened again?" Worth asking on a calm day. You are establishing whether you would hear about an incident at your provider at all.

If you do not use an outside provider, the same questions apply to whoever runs your remote support tooling internally. The platform is different, the shape is identical.

The general lesson

Your security is not only about your own systems. It includes every supplier holding a set of keys to them, and remote monitoring platforms hold the largest set of keys of all: administrative control of every machine they manage, for hundreds of businesses at once. That concentration is exactly what makes them worth attacking.

This is not an argument for firing your IT provider or ripping out remote support. The economics of running a business without it are terrible, and doing it yourself badly is worse than paying someone to do it well. It is an argument for knowing which platform yours uses, keeping the version conversation on the table, and expecting a straight answer when something goes wrong.

Good providers will welcome the question. The reaction to it tells you something either way.

How Steelwise can help

Working out which suppliers hold administrative access to your systems, and what you would actually be told if one of them were compromised, is a defined piece of work with a clear answer at the end. Get in touch if you want a second opinion on yours.

Further reading

← All filings