On 19 August, the Australian Signals Directorate’s Cyber Security Centre issued a high alert titled, without much ceremony, “Act quickly.” Most of the organisations who should read it have never heard of the product it names, and that is exactly the reason it is worth five minutes of anyone’s time, because the platform in question is not something you run, it is something your provider runs on your behalf, and that gap is the whole story.

The product is N-able N-central, a remote monitoring and management platform that managed service providers use to administer their clients’ laptops, servers and networks from a single console. Two authentication bypass flaws in it, CVE-2026-18556 and CVE-2026-18577, both rated 8.2 out of 10, allow an attacker to gain unauthorised access through what ACSC describes as an alternate path or channel, and both affect every current version of the platform, including the most recent release. N-able issued an initial patch on 2 August, but within a day or two, researchers found a second way through the same door that the first fix never closed, which is why there are two CVE numbers rather than one, and why a second hotfix followed before the platform was genuinely shut.

What makes this worse than an ordinary patch cycle is what the flaw actually hands an attacker. Once inside an N-central server, an intruder can use the platform’s own Take Control feature to reach every device it manages, which is precisely the capability ACSC’s own alert flags as the real danger: a single compromised console becomes, in the regulator’s words, an efficient path to compromise downstream managed systems. Worse again, attackers observed in the wild have been deploying Cloudflare tunnels as a foothold on the managed endpoints they reach, and a tunnel like that needs no inbound firewall rule and no open listening port to keep working, so patching and remediating the N-central server itself does not necessarily evict an attacker who has already used it to get further downstream.

ACSC’s alert is addressed, in its own words, to all Australian managed service providers and enterprise IT organisations that utilise the N-able N-central product, and small and medium businesses are told, plainly, to go and check with their MSP or IT provider about their exposure. That instruction is the part worth sitting with, because it is an admission that the regulator cannot tell you directly whether this affects you. Only your provider can, and right now, most organisations genuinely do not know the answer without asking.

The four questions worth asking this week

None of these require technical depth to ask, only the discipline to actually ask them and to expect a specific answer rather than a reassurance. Does your provider run N-able N-central to manage your environment at all. If so, has the current hotfix actually been applied, not just scheduled. Is the management interface exposed to the internet, or restricted to a private network. And has N-able’s own indicator-of-compromise script been run against your environment, with a result you have actually seen.

If your provider can answer all four cleanly and immediately, that is itself useful evidence. If they cannot, or the answer takes a week to come back, that delay is the risk, not the vulnerability itself.

Why almost nobody can answer this today

Here is the uncomfortable part, and it has very little to do with N-able specifically. Third-party risk in most organisations is currently assured through an annual questionnaire and a general sense of trust in the relationship, rather than through anything that would tell you, on the day a regulator issues a high alert, whether you are exposed right now. A questionnaire answered in March tells you what a provider said about their environment in March. It says nothing about a CVE published in August, and it certainly cannot tell you whether the specific hotfix landed on the specific server that reaches your specific endpoints.

The uncomfortable truth in this alert isn’t really about N-able. It’s that almost nobody reading it can currently answer, inside the next hour, whether it applies to them.

This is a smaller, faster-moving version of exactly the problem that CPS 230’s major supplier obligations, and the Enhanced CIRMP Rules for energy and utilities operators, are both trying to force into the open. You cannot discharge accountability for a supplier’s control failure by having once asked them a question on a form and filed the answer. What both frameworks are actually asking for is a live, evidence-based position on the providers who have the technical ability to reach your systems, refreshed continuously rather than reconstructed under pressure the day something goes wrong.

What this looks like run properly

At BayRisk, this is the exact category of question our clients don’t have to chase down themselves under pressure, because it’s already part of how we run their risk position on an ongoing basis rather than once a year. When an alert like this lands, the providers who can reach a client’s environment, and what they run, and whether it’s current, is already known rather than something we have to go and ask for the first time. That’s the difference between third-party risk as an annual form and third-party risk as an operation: one of them can answer this week’s question by Friday, and the other one is still waiting on an email back from the provider.

If this alert has sent you looking for an answer your own provider hasn’t given you yet, that’s a reasonable conversation to have: hello@bayrisk.com.au.

Sources