Web_Logo
Remote Support
Security Alert: Remote Management Software Under Attack
Home » Security Alerts  »  Security Alert: Remote Management Software Under Attack

Security Alert: Remote Management Software Under Attack

A vulnerability in remote monitoring and management (RMM) software used by IT providers worldwide is being actively exploited by attackers, according to the US Cybersecurity and Infrastructure Security Agency (CISA).

  • What it is: Two related authentication bypass flaws in N-able N-central, a platform many IT providers use to remotely monitor and manage business networks, allow an attacker to skip the login process entirely.
  • Who is affected: Businesses whose IT provider uses N-central. CISA also added actively exploited flaws in Apache Tomcat and the AI platform Langflow to its watchlist this week, affecting a broader range of business and developer tools.
  • What the risk is: Successful exploitation gives an attacker administrative access to the console used to manage a business's IT systems, potentially reaching every device it monitors.
  • What action is needed: N-able has released patches for both flaws. Businesses using an RMM platform should confirm with their IT provider that vendor patches have been applied.

We keep the management tooling used across our client base patched as a priority whenever advisories like this are issued.