Skip to main content
Emerging ThreatsMalware & Ransomware

MSPs Warned to Secure RMM Software Against Rising Attack Threats

Rack-mounted servers and equipment in a network operations center with a focus on a central server group.

“N-able shipped an emergency hotfix for CVE-2026-86218,” and roughly 1,500 servers were exposed online — the vendor’s fourth hotfix in five weeks, according to BleepingComputer. That sentence captures both the scale and the speed at which remote monitoring and management (RMM) platforms can become an operational crisis for managed service providers (MSPs).

N-able’s hotfix, exposed servers, and why the management plane matters

RMM “gives technicians unattended administrative access across thousands of customer devices,” the source notes, which makes the management plane an attractive target: “compromise one privileged account or server and the blast radius extends far beyond a single endpoint.” BleepingComputer’s September 2026 reporting about CVE-2026-86218 — one of multiple hotfixes over a five-week period — illustrates how quickly vulnerabilities in RMM infrastructure can affect large numbers of servers. The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA) has warned that ransomware actors abuse legitimate RMM software to reach downstream customer networks, underscoring the operational risk when the management layer is compromised.

Microsoft SharePoint “ToolShell” zero-days and the cost of patching lag

Earlier precedent reinforces the point. BleepingComputer’s July 2025 coverage of the Microsoft SharePoint “ToolShell” zero-days (CVE-2025-53770 and CVE-2025-53771) described exploits used before patches were available and reported at least 85 on‑premises servers compromised. One strike targeted a management plane; another showed how fast customers become exposed when exploitation outpaces patching.

The eight controls MSPs should test

Rather than choosing an RMM product by feature count, the source advises MSPs to test outcomes directly. Acronis — which says it built this checklist from securing endpoint management across thousands of customer environments — identifies eight specific controls:

  • Endpoint discovery and inventory: continuously find and classify endpoints, servers, network devices and software assets.
  • Risk‑based patch management: prioritize updates, handle deployment failures, and support rollback.
  • Access controls and privileged administration: multifactor authentication, role‑based access controls and separation of duties.
  • Alert prioritization and operational visibility: reduce duplicate and non‑actionable alerts that create fatigue.
  • Secure automation and scripting: approval controls, auditing and execution visibility for scripts.
  • Integration with security operations: seamless movement from investigation to remediation and recovery.
  • Recovery readiness: ensure backup, patching, remote access and incident response work together during a restore.
  • Tenant separation and auditability: keep policies, permissions, reports and administrative actions isolated between client environments.

The guidance includes practical testing actions — for example, introduce a new device to measure discovery time, simulate a failed patch to reveal deployment gaps, or create a restricted technician role to verify separation of duties.

Access controls, automation and audit trails: the governance trifecta

Three technical controls recur across the checklist and the incident history: identity and access management for technicians, governance of automation and scripting, and exhaustive audit trails. The source recommends multifactor authentication, role‑based access, and separation of duties as baseline requirements for technician accounts; it also stresses approval workflows and execution visibility for scripts that can act across many devices. Detailed audit trails are necessary not just for compliance reporting but for investigating whether policies, permissions and administrative actions remained isolated between tenants.

Recovery readiness and Acronis Cyber Platform’s approach

Security, the source emphasizes, is as much about recovery as prevention. Acronis says its Cyber Platform pairs RMM with backup and anti‑malware scanning of recovery points (where included in the service package) so a restore is validated for integrity and outstanding vulnerabilities before a system goes back online. The practical test recommended: verify that restored systems return to a secure and fully updated state, and confirm that recovery paths remain usable even if the management workflow is compromised.

What this means for technologists, procurement leaders, and enterprise customers

Technologists and security teams should run the deliberate scenarios the source prescribes — an unmanaged endpoint, a failed patch, an unauthorized script, a compromised test device — to validate detection, containment and recovery workflows. Procurement leaders ought to map licensing and service packages to the eight controls rather than assume every capability is included; Acronis warns that available capabilities and licensing vary by package. Enterprise customers should demand evidence of tenant separation, auditable technician activity and a tested recovery path that does not rely on an uncompromised management console.

Bottom line: RMM is a high‑value attack surface because of the privilege it grants and the scale it controls. MSPs that pilot the specifically difficult scenarios named here — and verify identity controls, patching behavior, automation governance, and recovery validation — will be better positioned to keep their customers’ environments resilient when vulnerabilities or exploits emerge.

https://www.bleepingcomputer.com/news/security/how-to-secure-rmm-software-8-controls-msps-should-test/