Mission

RMM Tool Hacked: Emergency Playbook for Small Business

RMM Tool Hacked: Emergency Playbook for Small Business

Know what attackers see before they do. See a sample Radar scan report →

Your RMM platform is the skeleton key to your entire business. It can push software, wipe endpoints, change passwords, and access every machine on your network — all from a single pane of glass. That's exactly why attackers want it.

This week, that threat stopped being theoretical.

What Just Happened: CISA's Active Exploit Warning

According to The Hacker News, CISA has officially added CVE-2026-9198 — a critical N-central vulnerability with a CVSS score of 9.8 — to its Known Exploited Vulnerabilities catalog. That's the federal government confirming: this isn't a theoretical risk. Attackers are using it right now, in the wild, against real targets.

Then it got worse. According to Security News, a second authentication bypass flaw (CVE-2026-18577) was discovered over the weekend in N-able's RMM platform. This one hands attackers administrator-level access. Two critical vulnerabilities, two emergency patches, days apart — and if you're running any N-central version prior to 2026.3, you are exposed on both counts.

This is not a drill.

Why RMM Attacks Are Uniquely Catastrophic

Most cyberattacks target one system. An RMM compromise targets every system you manage.

Security News documented a campaign called Smoke#Screen in which threat actors used social engineering to deliver ScreenConnect — a legitimate remote management tool — as a backdoor into managed networks. The attacker playbook is now well-established: gain RMM access, move laterally across all connected endpoints, deploy ransomware or exfiltrate data at scale.

For context on how supply chain logic amplifies this damage: The Hacker News reported on the QuickFox campaign, in which a trojanized Windows installer silently delivered the FDMTP backdoor to thousands of endpoints. A compromised RMM tool works the same way — your trusted management channel becomes the delivery mechanism for malicious payloads across every client or machine you oversee.

If you manage 50 endpoints, you have a 50-machine problem. If you're an MSP managing 20 clients, you have a 20-client crisis.

The Emergency Playbook: What to Do Right Now

Step 1: Verify Your RMM Version Immediately

Log into your N-central console and check your current version. If you are running anything prior to 2026.3, stop reading and go patch. Both CVE-2026-9198 and CVE-2026-18577 are actively exploited. Apply the vendor-issued patches before doing anything else.

Not sure how to check? Your N-central dashboard displays the build version in the bottom footer or under Administration > System Information.

Step 2: Audit Active RMM Sessions

Go to your RMM's session and agent logs. Look for: - Sessions initiated outside business hours - Logins from unfamiliar IP addresses or geographies - New agents installed on endpoints you don't recognize - Bulk script executions or software deployments you didn't authorize

Any of these is a red flag. Document what you find before taking further action.

Step 3: Rotate All Credentials Associated with the RMM

Assume breach posture. Rotate: - The RMM admin account password - Any service accounts the RMM uses - API keys and integration tokens - Credentials stored within the RMM (many platforms cache endpoint admin passwords)

This is not optional. Authentication bypass vulnerabilities mean attackers may have already established persistence using your existing credentials.

Step 4: Isolate Suspicious Endpoints

If your audit in Step 2 flagged anything unusual, isolate those endpoints from the network immediately. Do not attempt to clean them while they remain connected — you risk giving an active attacker time to pivot. Pull the network cable or use your EDR to isolate remotely if the RMM itself is untrusted.

For guidance on endpoint isolation and detection, our post on Huntress vs Windows Defender for endpoint security covers what a layered detection approach looks like for small teams.

Step 5: Notify Affected Parties

If you are an MSP or IT admin managing multiple clients, your disclosure obligations kick in immediately. Do not wait until you have full forensics. Notify clients that a vulnerability in your management tooling was actively exploited, describe what you've done to remediate, and provide a timeline for further updates. Silence is not a strategy — it's a liability.

For more on the legal exposure this creates, see our breakdown of ransomware liability and small business legal risk.

Step 6: Harden Your RMM Configuration Going Forward

Once the immediate fire is out: - Enable MFA on all RMM admin accounts (no exceptions) - Restrict RMM console access to known IP ranges via allowlisting - Disable unused agent features and integrations - Set up alerting for after-hours logins and bulk script executions - Review your patch cadence — both CVEs above were patchable before exploitation began

If you're running a self-hosted RMM instance, the attack surface is even larger. Our post on self-hosted RMM security risks walks through the additional hardening steps that apply to on-prem deployments.

The Uncomfortable Truth About Tool Trust

We grant RMM platforms implicit, sweeping trust because they make our jobs manageable. But that trust is exactly what makes them high-value targets. The Smoke#Screen campaign and the QuickFox supply chain attack both exploit the same principle: once you trust the delivery channel, you stop questioning the payload.

The answer isn't to abandon RMM tools — it's to stop treating them as inherently safe. Verify versions. Audit sessions. Rotate credentials on a schedule, not just after incidents. And maintain a detection layer that operates independently of your RMM, so that if the management plane is compromised, you still have visibility.

Small businesses with limited staff don't have the luxury of a 48-hour incident response team. That's exactly why having a repeatable playbook — and running regular external scans to catch exposed services before attackers do — matters more, not less.


Take Action: Don't Wait for the Next Advisory

The N-central vulnerabilities are patched — but the attackers who already have footholds from the exploitation window aren't going away. And the next critical RMM CVE is already being researched.

Proactive scanning catches exposed services, outdated software versions, and misconfigured management interfaces before they show up in a CISA advisory with your name attached to the incident report.

Oscar Six Security's Radar gives small businesses and IT admins an affordable way to scan their external attack surface for exactly these kinds of exposures — for $99 per scan. No enterprise contract. No waiting.

Focus Forward. We've Got Your Six.

Frequently Asked Questions

What should I do if my RMM software has a critical vulnerability?

Patch immediately to the vendor's latest version, then audit all active sessions and logs for unauthorized access. Rotate all credentials associated with the RMM — including service accounts and API keys — and enable MFA if it isn't already active. If you suspect active compromise, isolate affected endpoints before attempting remediation.

Is N-central RMM safe to use right now?

N-central is safe to use if you have patched to version 2026.3 or later, which addresses both CVE-2026-9198 and CVE-2026-18577. CISA confirmed CVE-2026-9198 (CVSS 9.8) is actively exploited in the wild, so any unpatched instance should be treated as compromised until proven otherwise. Run an external scan with a tool like Oscar Six Radar to verify no management interfaces are exposed to the public internet.

How do hackers use RMM tools to attack businesses?

Attackers exploit authentication vulnerabilities or use social engineering to gain access to RMM platforms, then leverage the tool's legitimate capabilities — script execution, software deployment, credential access — to move laterally across every managed endpoint. Because RMM tools are trusted by design, security controls often don't flag their activity as suspicious, making detection difficult without independent monitoring.

How much does a vulnerability scan cost for a small business?

Enterprise vulnerability management platforms can cost thousands of dollars per year, but Oscar Six Security's Radar offers external attack surface scans for $99 per scan — no subscription required. This makes it practical for small businesses and IT admins to run scans after major vulnerability disclosures or before audits without a large budget commitment.

What is a software supply chain attack and how does it affect my RMM?

A software supply chain attack occurs when attackers compromise a trusted piece of software — an installer, update, or integration — to deliver malicious payloads to everyone who uses it. RMM platforms are high-value supply chain targets because a single compromised management tool can push malicious scripts or backdoors to thousands of endpoints simultaneously, amplifying the attacker's reach dramatically.

Step-by-Step Guide

  1. Verify RMM Version

    Log into your N-central console and confirm you are running version 2026.3 or later. If not, apply the vendor patch immediately before taking any other action.

  2. Audit Active Sessions and Logs

    Review RMM session logs for logins outside business hours, unfamiliar IP addresses, unauthorized agent installations, or bulk script executions you did not initiate.

  3. Rotate All RMM Credentials

    Change the RMM admin password, rotate all service accounts, API keys, and integration tokens, and update any endpoint credentials stored within the RMM platform.

  4. Isolate Suspicious Endpoints

    If your log audit flagged any unusual activity, immediately isolate those endpoints from the network using your EDR or by physically disconnecting them before attempting cleanup.

  5. Notify Affected Clients or Stakeholders

    If you manage multiple clients, disclose the vulnerability event promptly, describe remediation steps taken, and provide a timeline for follow-up — silence creates legal and reputational liability.

  6. Harden RMM Configuration

    Enable MFA on all admin accounts, restrict console access to known IP ranges, disable unused integrations, and configure alerts for after-hours logins and bulk operations.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →