At the end of July 2026, attackers began exploiting a zero-day in N-able N-central — the remote monitoring and management (RMM) platform that thousands of managed service providers (MSPs) use to patch, monitor and remotely access their customers' servers and workstations. The flaw, now tracked as CVE-2026-18577, is an authentication bypass: no stolen password needed, no phishing email, no malware on your side. The attacker walks straight into the console that already has administrator rights over your infrastructure.
If your company outsources IT administration — and most Romanian SMEs and many larger organisations do — this incident is not a story about someone else's software. It is a demonstration of your own attack surface.
What actually happened
According to N-able and researchers who tracked the campaign, the timeline was short and uncomfortable. The vendor noticed unusual activity on July 31 and confirmed active exploitation on August 2. The bug turned out to be a bypass of the patch for an earlier vulnerability (CVE-2026-18556), meaning attackers studied the fix and found a way around it.
Once inside an N-central server, the attackers did exactly what an MSP technician can do: they used the platform's legitimate Take Control remote-access feature to connect to systems managed through the console, then registered a Cloudflare tunnel as a service on those endpoints to keep access even after the hole was closed. N-able has confirmed that attackers reached customer networks, released two hotfixes in quick succession (version 2026.3.1.7, then a second hotfix with further hardening), and CISA added the flaw to its Known Exploited Vulnerabilities catalogue, giving US federal agencies just days to patch.
Note the mechanics: no exploit was needed on the victims' machines. The trust relationship was the exploit path.
Why this is a NIS 2 problem, not just an IT problem
NIS 2 — transposed in Romania through OUG 155/2024, with the scope further extended by Law 124/2025 — makes supply-chain security an explicit legal obligation, not a nice-to-have. Essential and important entities must address, as part of their risk-management measures, the security of relationships with direct suppliers and service providers. That includes, very specifically, providers of managed services: the directive's recitals single out MSPs and MSSPs precisely because of the privileged access they hold.
Three consequences matter for Romanian companies:
- You stay responsible. Outsourcing IT administration does not outsource liability. If an attacker reaches your systems through your MSP's tooling, the incident is your incident, with your reporting obligations to DNSC (initial warning within 24 hours, incident notification within 72 hours) and your potential sanctions — up to €10 million or 2% of worldwide turnover for essential entities, €7 million or 1.4% for important ones.
- Management is personally on the hook. OUG 155/2024 mirrors the directive's provisions on management responsibility: leadership must approve the risk-management measures, oversee their implementation and can be held accountable for failures — supply-chain measures included.
- Your MSP may itself be a NIS 2 entity. DNSC can also designate organisations with a critical role in a supply chain as NIS 2 entities regardless of size. Several compliance advisories expect supply-chain deficiencies to become one of the main grounds for sanctions as DNSC controls intensify from 2026 onwards — a vendor- and consultant-reported expectation, but a plausible one given how the enforcement phase is unfolding.
The three levers NIS 2 gives you: contract, audit, verification
What does "managing supplier risk" mean in practice, when the supplier holds a domain-admin-equivalent console over your network?
1. Contractual security clauses. Your contract with an IT provider should stop being a pure SLA about response times. It needs: minimum security requirements for the provider's own infrastructure (MFA everywhere, patching timelines for their tooling, network segmentation of their management plane); a binding obligation to notify you of security incidents affecting their systems within a defined number of hours — not "without undue delay" left undefined; a list of subcontractors and fourth parties with access; and clear exit provisions covering the return of credentials and removal of agents.
2. Right to audit and to test. A clause on paper means little if you can never check it. Negotiate an explicit right to audit the provider's controls — questionnaires at minimum, on-site or independent audits for critical providers — and the right to include the provider's access paths in your own security testing. A penetration test that ends at the boundary of "that's the MSP's system, out of scope" is testing a fiction: attackers demonstrably do not respect that scope line. An infrastructure penetration test should model exactly the N-central scenario — what can someone do from the management platform, and would you detect it?
3. Verification of privileged third-party access. This is the control most organisations skip. Concretely: keep an inventory of every external account, agent and RMM tool with privileged access to your environment; enforce MFA on the provider's accounts in your systems, not just theirs; restrict the management platform's network access to what it needs; log and alert on remote-control sessions (a Take Control connection at 03:00 should page someone); and review quarterly whether each access still needs to exist. Dormant vendor accounts and forgotten agents are exactly what the N-central attackers relied on to persist.
Questions to send your IT provider this week
- Do you use N-central or another RMM? Which version, and when were the August hotfixes applied?
- Is MFA enforced on all technician accounts, including API access?
- How would you know — and how quickly would you tell us — if your management platform were compromised?
- Which of your staff and subcontractors can open a remote session to our systems today?
- Will you accept a contractual audit-and-testing clause at renewal?
An honest provider answers these in a day. Evasive answers are themselves a risk-assessment result.
If you want a structured starting point, our NIS 2 / DORA checklist covers the supply-chain requirements alongside the other measures, and our audit and compliance team can map your current supplier contracts against what OUG 155/2024 actually expects. The N-central campaign will not be the last time an attacker chooses the management plane over the front door — it is simply the cheapest way in.
This article provides general information, not legal advice. Sources: The Hacker News, BleepingComputer, Rapid7, Help Net Security, CMS Law on Law 124/2025.

