GCS Threat Briefing
Threat Landscape

The Incomplete Patch

G
Jonathan Garzon
Founder & CEO, Garzon Cyber Solutions
August 2026, updated 11 August · 7 min read
GCS Threat Briefing: The Incomplete Patch. Attackers bypassed the first fix for an authentication bypass in N-able N-central, the platform that runs thousands of outsourced IT estates, shown with a large faded 8.2 CVSS numeral in the Garzon Cyber Solutions brand colours.

A vendor shipped a fix. Attackers bypassed it. A second CVE had to be issued, an emergency hotfix released, and within twenty-four hours the flaw was in CISA’s Known Exploited Vulnerabilities catalogue. Every organisation that applied the first patch in good faith remained exploitable throughout. That is the story, and it is not really a story about N-able.

What happened

N-able N-central is a remote monitoring and management platform. It is the control plane thousands of managed service providers use to administer their clients’ IT estates: deploy software, apply patches, take remote control of endpoints. It is, by design, one of the most privileged systems in any environment it touches.

In late July, N-able disclosed CVE-2026-18556, an authentication bypass carrying a CVSS score of 8.2, which allows an unauthenticated attacker to obtain administrative access to an N-central server. A fix was issued. Researchers subsequently established that the fix could be circumvented. A second identifier, CVE-2026-18577, was assigned to the bypass, also scored 8.2, and an emergency hotfix followed.

8.2CVSS, authentication bypass in N-central
2CVEs, because the first fix could be bypassed
6 AugCISA remediation deadline for US federal agencies

The exploitation activity is what elevates this above routine patch management. Huntress reported attackers using the compromised console’s own Take Control feature, a legitimate built-in remote access capability, to pivot from the management server into managed endpoints, including domain controllers. Cloudflare-based tunnels were then deployed to maintain access. N-able has confirmed that a limited number of customers were compromised through the second vulnerability.

Update, 10 August: attribution

On 10 August, Microsoft Threat Intelligence published its assessment of the activity. From 2 August it observed Storm-1175, a China-based financially motivated actor previously associated with Medusa ransomware, deploying a new ransomware strain it calls StormEncryptor. Microsoft separately reports LSASS credential dumping within the same activity, so any organisation in scope should treat privileged credentials as potentially exposed rather than merely at risk.

The confidence distinction matters here and is easy to invert. Microsoft attributes the StormEncryptor deployments to Storm-1175 as a finding. What it qualifies is the initial access vector: it states that the exact vulnerability exploited is unclear and that CVE-2026-18577 is the likely route. The ransomware and the actor are established. The link to this specific CVE is an assessment, not a confirmed fact.

That distinction does not soften the operational conclusion. The interval from silent zero-day on 31 July to observed ransomware deployment on 2 August was roughly two days. No patch cycle absorbs that, which is why the response has to be detection and hunting rather than remediation alone.

Timeline infographic titled Two days from zero-day to ransomware, covering CVE-2026-18577 from 31 July to 10 August 2026. Unusual activity flagged and zero-day exploitation discovered on 31 July. Vendor discloses active exploitation on 1 August. Hotfix 1 build 2026.3.1.7 released and StormEncryptor deployment observed on 2 August. Added to the CISA Known Exploited Vulnerabilities list on 3 August. Hotfix 2 build 2026.3.1.10 released on 6 August, required even if Hotfix 1 was applied. Microsoft publishes its assessment on 10 August attributing activity to China-based Storm-1175, likely via this flaw.
The full sequence, 31 July to 10 August 2026. Roughly two days from silent zero-day to observed ransomware deployment. Sources: N-able advisories, Rapid7, Sophos, Huntress, Microsoft Threat Intelligence, CISA KEV, Help Net Security, BleepingComputer.

Why this one is different

Most vulnerability news is noise. This one carries two features that make it materially more serious than its CVSS score suggests.

The patch was not a patch

Vulnerability management, as practised in most organisations, is a binary process. A patch is released, it is applied, the ticket is closed and the risk register is updated. That model assumes the fix works.

Here it did not. Organisations that responded promptly, applied the vendor’s remediation and recorded the control as satisfied were still exploitable. Their vulnerability scanners would have reported compliance. Their patch dashboards would have shown green. They were wrong, and nothing in their process was capable of telling them so.

Applying a patch is a task. Confirming it holds is a control. Most organisations fund the first and assume the second.

The blast radius is one-to-many

A compromised RMM console is not a single-organisation incident. It is a distribution channel. Access is inherited across every managed estate, and it arrives through a trusted, whitelisted mechanism that endpoint controls are specifically configured not to obstruct.

This is the pattern established by Kaseya in 2021 and reinforced by every major supply chain compromise since. The attacker does not need to breach the target. They breach the entity the target has already decided to trust.

Infographic titled One console, every client, showing four escalation stages. Stage one, authentication bypass: an unauthenticated attacker gains administrative access to the N-central console. Stage two, Take Control abused: the platform's own legitimate remote access feature is used to reach managed endpoints. Stage three, domain controllers reached: access extends into client environments through a trusted, whitelisted channel. Stage four, persistence established: Cloudflare-based tunnels are deployed to retain access after remediation.
How access to a single management console propagates into every downstream client estate. Source: Huntress incident reporting.

The commercial exposure

For a board, the operative question is not whether N-central is patched. It is what this class of event costs when it lands, and who carries it.

Regulatory. Under UK GDPR, the ICO assesses whether an organisation had “appropriate” technical and organisational measures in place. Recent ICO enforcement decisions have leaned heavily on NCSC guidance to define that standard, and the regulator has been explicit that supplier oversight forms part of it. The Cyber Security and Resilience Bill will extend statutory duties to managed service providers directly. Organisations inside NIS2 or DORA already carry formal, auditable third-party risk obligations. In none of these regimes is “our provider handled it” a recognised position.

Contractual. Most MSP agreements in the mid-market specify availability, not security posture. They rarely contain a patch application SLA, a right to audit, or a notification obligation on vendor advisories. When an incident originates upstream, the client discovers that the contract allocates the operational work to the provider and the legal liability to themselves.

Insurance. Cyber policies increasingly underwrite on demonstrated control operation rather than stated policy. An insurer examining this incident will ask when the hotfix was applied and what evidence exists. A gap in that record is a coverage argument.

Reputational and commercial. Enterprise security questionnaires now routinely ask how supplier patch compliance is verified. A firm that cannot answer does not fail loudly. It fails quietly, at the procurement stage, months before anyone in the commercial function connects the two.

What to do this week

The technical response is straightforward and should already be complete. Confirm N-central is running version 2026.3 HF1 or later. Review Take Control session logs and administrative account creation from 1 August onwards. Hunt for unauthorised Cloudflare tunnel activity and anomalous outbound connections from the management server.

The governance response is the part most organisations will skip. If your IT is outsourced, the version number is not yours to check. It has to be requested, in writing, from the provider.

Infographic titled Four questions for your provider, to be asked in writing. Version: which N-central version are we running, and is it 2026.3 HF1 or later? Evidence: what Take Control session activity has been reviewed since 1 August, and by whom? Exposure: was our environment among those affected, and how was that determined? Process: how are you notified of vendor patches, and what is your applied-by commitment to us? A closing panel states that if an answer takes more than 24 hours, that is your finding.
A supplier assurance request that takes five minutes to send and produces evidence you can put in front of a regulator, an insurer or an enterprise client.

Three questions for leadership

1. For every supplier with privileged or administrative access to our environment, do we know what they run, what version it is on, and how quickly they apply critical patches? If not, what is that gap worth in a claim or an enforcement action?

2. When we mark a vulnerability as remediated, what evidence supports that judgement beyond the fact that a patch was installed? Who is accountable for confirming the fix actually holds?

3. If our provider were compromised tomorrow, what in our contract obliges them to tell us, how quickly, and what are we entitled to see?

If those three cannot be answered in a single meeting, the exposure is not in the patch cycle. It is in the operating model.

The strategic takeaway

Outsourcing IT transfers the work. It does not transfer the risk, the regulatory duty or the commercial consequence. Those stay exactly where they were.

What this incident makes plain is that the assurance layer most organisations rely on, an annual questionnaire and a trusted relationship, cannot detect a vendor fix that does not work. Nothing in that process would have surfaced the gap between 2 and 6 August. Something else has to.

Supplier assurance is not a procurement formality. It is the control that determines whether someone else’s patch cycle becomes your breach.

Do you know what your provider is running?

A focused review of third-party and supplier assurance: privileged access mapping, contractual security obligations, and an evidence trail that stands up to a regulator, an insurer or an enterprise security review.

Start the Conversation →

Sources: N-able, N-central Security Update, 2 August 2026. Cybersecurity and Infrastructure Security Agency, Known Exploited Vulnerabilities Catalog. Huntress, incident reporting on N-able N-central exploitation. The Hacker News. IT Security Guru. Security Affairs. Tenable. Microsoft Threat Intelligence, assessment published 10 August 2026. Rapid7. Sophos. Help Net Security. BleepingComputer. Note on confidence: Microsoft attributes the StormEncryptor deployments to Storm-1175 as a finding. It qualifies the initial access vector, stating the exact vulnerability exploited is unclear and that CVE-2026-18577 is the likely route. GCS Threat Briefings translate active incidents into the governance and commercial decisions boards and security leaders need to make.

#CyberSecurity #ThirdPartyRisk #SupplyChainSecurity #MSP #CISO #Governance #GarzonCyberSolutions

Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent inside cybersecurity and compliance across the sales, marketing and technical sides of the industry.