Compliance

RMM Vulnerabilities: How to Audit and Harden Your Tools

RMM Vulnerabilities: How to Audit and Harden Your Tools

Know what attackers see before they do. See a sample Radar scan report →

If you manage IT for a small business or a handful of clients, your RMM platform is probably the single most powerful piece of software in your environment. It has admin rights on every endpoint it touches, it runs 24/7, and it's reachable from the internet by design. That's exactly why attackers have started treating RMM software as the shortest path into your network — not as a tool to abuse after a breach, but as the breach itself.

The Reddit Alarm Bells Were Right

A wave of urgent hotfix posts recently described a zero-day in N-central allowing pre-authenticated server access — meaning an attacker didn't even need valid credentials to reach the system. That's not a theoretical risk; it's a direct line into whatever N-central manages.

According to The Hacker News, N-able has now issued its fourth N-central hotfix in five weeks, this time for an unauthenticated remote code execution flaw, with conflicting reports about whether it's already being exploited in the wild. Four emergency patches in five weeks isn't a one-off bug — it's a pattern that says the platform's attack surface is actively being probed, and vendors are racing to stay ahead of it.

And it's not isolated to one vendor. According to The Hacker News, rogue ScreenConnect clients have been observed spreading a four-stage VBScript chain to newly connected hosts, essentially worming through remote-access infrastructure the moment a new machine joins. Two of the most widely deployed RMM platforms on the market, hit with serious exploitation activity in the same week. That's a category problem, not a vendor problem.

Why This Hits Small Business IT Harder Than MSPs

MSPs at least have escalation paths, vendor relationships, and (usually) someone watching security advisories. A solo sysadmin or a small business owner running their own IT often doesn't find out about an emergency hotfix until it's already old news — or until something breaks. If you're managing your own environment without dedicated security staff, you need a lightweight, repeatable process for treating RMM patches like the critical infrastructure they are, not like routine software updates.

The Audit Checklist: Harden Your RMM Before It's Used Against You

This isn't about ripping out your remote management tool. It's about auditing how it's configured, patched, and monitored so a vulnerability doesn't become an incident.

  1. Inventory every RMM agent in your environment. You can't patch what you don't know exists. If you've ever inherited machines from a prior IT provider, this step alone often turns up surprises — see our guide on detecting unauthorized software and rogue agents for a walkthrough.
  2. Restrict internet-facing access. If your RMM server or console doesn't need to be reachable from the open internet, put it behind a VPN or IP allowlist. Pre-auth exploits only work if the vulnerable service is reachable in the first place.
  3. Turn on vendor security notifications directly — don't rely on stumbling across a blog post or a forum thread. Subscribe to the vendor's security bulletin RSS or email list for your specific platform.
  4. Set a 24-48 hour SLA for critical RMM patches. Treat hotfixes for pre-auth or unauthenticated RCE flaws the same way you'd treat a firewall zero-day — patch first, ask questions later.
  5. Review agent permissions and scope. Does every deployed agent actually need full administrative access, or can some be scoped down? Least privilege applies to your management tools too.
  6. Audit who has access to the RMM console itself, and enforce MFA on every account with access. A compromised console credential is functionally equivalent to a pre-auth exploit if MFA isn't enforced.
  7. Log and monitor RMM authentication and deployment events. Unexpected new agent installs or logins from unfamiliar IPs are early warning signs worth alerting on.

If you're unsure whether an agent on your network is legitimate or rogue, our post on unauthorized RMM agent detection walks through the signs to look for. And if you've already had an RMM incident, our emergency playbook for a hacked RMM tool covers the response steps in detail.

The Bigger Lesson: Patch Cadence Has Changed

Four hotfixes in five weeks for one platform, plus active worming behavior on another, tells you the old model — check for updates monthly, patch during a maintenance window — no longer matches the threat. RMM vendors are shipping emergency fixes on compressed timelines because attackers are moving fast. Your patch process has to move at the same speed, or the gap between disclosure and exploitation becomes your exposure window.

Take Action

You don't need a full-time security team to catch these gaps — you need visibility into what's exposed before an attacker finds it first. Oscar Six Security's Radar scan checks your external attack surface, including exposed management consoles and known vulnerable services, for a flat $99 per scan. It's a fast, affordable way to confirm your RMM tooling and other internet-facing systems aren't sitting on a known exploit path. Check out our Solutions page to get started.

Focus Forward. We've Got Your Six.

Frequently Asked Questions

What is a pre-authenticated RMM vulnerability?

A pre-authenticated vulnerability allows an attacker to access or execute code on a system without needing valid login credentials first. In RMM software, this is especially dangerous because a successful exploit can hand over control of every endpoint the platform manages.

How often should I patch my RMM software?

Critical or emergency RMM patches, especially those addressing unauthenticated access or remote code execution, should be applied within 24-48 hours of release. Routine updates can follow a normal maintenance cadence, but pre-auth flaws require immediate action given how quickly they get weaponized.

Is N-central safe to use after these patches?

N-able has released hotfixes for the reported flaws, and applying them promptly closes the known exploitation paths. That said, the repeated emergency patches highlight the need for ongoing hardening — restricting internet exposure, enforcing MFA, and monitoring access logs — regardless of which RMM platform you run.

How can I check if my RMM console is exposed to the internet?

You can review your firewall rules and DNS records for any publicly resolvable RMM server addresses, or run an external vulnerability scan to see what's actually reachable from outside your network. Oscar Six Security's Radar scan ($99) is built for exactly this kind of external exposure check.

What should I do if I find an unauthorized RMM agent on my network?

Isolate the affected machine from the network immediately, then investigate how the agent was installed and whether it has been used to access other systems. Our detailed guide on unauthorized RMM agent detection walks through the full identification and removal process.

Step-by-Step Guide

  1. Inventory every RMM agent

    Identify all RMM software installed across your environment, including any left behind by previous IT providers or vendors.

  2. Restrict internet-facing access

    Put RMM consoles and servers behind a VPN or IP allowlist instead of leaving them directly reachable from the internet.

  3. Subscribe to vendor security alerts

    Sign up directly for your RMM vendor's security bulletin so you learn about emergency patches immediately, not by accident.

  4. Set a fast patch SLA

    Commit to applying critical or pre-auth RMM patches within 24-48 hours of release rather than waiting for a routine maintenance window.

  5. Review agent and console permissions

    Scope down agent privileges where possible and enforce MFA on every account with access to the RMM console.

  6. Monitor for anomalous activity

    Set up alerts for unexpected new agent installs, unfamiliar login locations, or unusual deployment activity within your RMM platform.

Find out what's exposed. Radar scans your external attack surface and shows you exactly what needs fixing. See a sample report →