N-able has disclosed a critical N-central vulnerability that can give an unauthenticated attacker full administrative access to the N-central console and the endpoints it manages. This article focuses on how to use Huntress RMM Guard to find where N-central agents are present in your environment.
For more details about the vulnerability, investigation guidance, and hardening recommendations, see:
- Support KB: 2026 - August N-Able Vulnerability
- Blog: Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation
How can RMM Guard help?
RMM Guard is a capability within Huntress Managed ESPM that automatically discovers remote monitoring and management (RMM) and other remote access tools across your Windows endpoints, and shows you where they are running and when they were last seen.
Because of the growing risk from RMM abuse, Huntress is making RMM Guard available at no additional cost while we build out Managed ESPM and prepare it for general availability. This article walks through using RMM Guard for discovery so you can identify endpoints where N-able N-central agents are still present.
Step 1: Join ESPM Early Access
- If you have not previously done so, click the ESPM icon in the left navigation of the Huntress Dashboard and click “Join Early Access For Free”
- Enable ESPM for the Account or Organizations you want to scan:
- Click the ESPM icon in the left navigation of the Huntress Dashboard.
- Select Settings.
- Set Account Settings to Enabled for account-wide coverage, or use Add Organization Override to enable specific organizations, then Save.
- For more detail, see Huntress Managed ESPM (Early Access) Readiness, Requirements, and FAQ.
Step 2: Let RMM Guard discover RMM tools
Once ESPM is enabled and endpoints are reporting, RMM Guard automatically discovers remote access tools that are running in your environment and lists them in the RMM Tools Inventory.
- After first enabling ESPM for an account or organization, allow up to 24 hours for RMM Guard to build a complete inventory.
- You can speed up discovery by restarting endpoints or the N-central services where appropriate.
- To view discovered RMMs, click the ESPM Icon in the left-hand navigation, then select RMM Guard.
Step 3: Filter for N-able N-central agents
In most environments, N-central agents will appear in RMM Guard as N-Able Advanced Monitoring Agent.
- In the RMM Tools Inventory, use the search to look for N-Able.
- Select the N-Able Advanced Monitoring Agent entry in the list. This opens a details panel showing the organizations and endpoints where this tool has been seen.
- Review and export the list as a CSV to confirm which clients and hosts you expect to be using N-central, and which ones are unexpected or legacy.
Step 4: Remediate N-central vulnerability
After you’ve identified affected endpoints, please follow our existing N-central guidance to either remove N-central where it shouldn’t be present or patch and harden the N-central server where it is still in use. Review these Huntress resources for additional information:
- Support KB: 2026 - August N-Able Vulnerability
- Blog: Rapid Response: Critical N-able N-central Vulnerability and Active Exploitation
We’d love to get your feedback
RMM Guard gives you a straightforward way to answer a specific operational question for this incident: which endpoints still have N-central agents installed, and where they live across your accounts and organizations. This is one use case for RMM Guard and the larger ESPM Product we are building. If you run into unexpected results, or have suggestions that would make RMM Guard more useful for this type of investigation, submit feedback at https://feedback.huntress.com/espm.