N-able said attackers exploited an authentication bypass in N-central, its remote monitoring and management platform, to gain administrative control over servers used to manage customer endpoints. The company shipped a fix. The attackers came back in anyway, which means the patch closed the entry point they used the first time, not the one they used the second. N-central sits in the position every RMM tool sits in: one compromised instance gives an intruder standing access to every downstream client network the managed service provider touches, which is why CISA has flagged RMM platforms as a named priority since the 2023 wave of similar intrusions.
For the managed service providers running N-central, the question isn't whether N-able's second fix works. It's whether they can tell the difference between "patched" and "attacker no longer has the specific foothold we found." Those aren't the same claim, and N-able's own admission that the first fix was incomplete is the evidence that nobody, including the vendor, had verified they were the same. The control that would have changed this outcome is credential rotation and session invalidation across every N-central-managed endpoint after the first disclosure, not a wait for patch two.