

About Author
Kristian Wright
Kristian Wright is CEO and co-founder of enhanced.io, a channel-only SOC-as-a-Service provider built for MSPs. He has over 30 years in IT leadership and has co-founded three service delivery businesses.
enhanced.io, the channel-only Open XDR SOCaaS for MSPs
TL;DR
Three separate RMM, SD-WAN and remote access platforms were hit by actively exploited vulnerabilities within weeks of each other this summer.
One vendor's first patch was incomplete. Attackers found a second way in before the follow-up fix shipped.
Identity, not endpoints, is the primary battleground now. Guardz's 2026 State of MSP Threat Report found 89 percent of monitored SMB environments had a confirmed credential compromise at some point.
Your own tooling usually gets less monitoring than the client environments it manages. That gap is exactly where these attacks land.
A short audit checklist below covers what to check on your own stack this month.
You patch your clients' systems every month. Ask yourself when you last patched the tool you use to do it.
That question stopped being theoretical this summer. enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT, and we watch this pattern across every partner environment we touch. The tools you run to deliver security are now a direct target, not just the path you use to protect someone else's network.
The summer's CVE list reads differently if you run the tools
In July, Arista patched a maximum-severity flaw in VeloCloud Orchestrator, the platform that centrally manages SD-WAN deployments. CVE-2026-16812 let an unauthenticated attacker run commands directly on the orchestrator host, no credentials needed, and it was already being exploited before the patch shipped.
Days later, SonicWall disclosed two chained flaws in its SMA1000 remote access appliances. One let an attacker open a tunnel to internal-only services with no login at all. The pair together gave a path to root. INC Ransomware has since become the most active group weaponizing that chain, with new victims still appearing on its leak site into August.
Then N-able's N-central RMM platform got hit twice. The first authentication bypass was patched. Attackers found a second path around that same patch days later, and N-able had to ship a follow-up hotfix. In the meantime, attackers used the platform's own remote access feature to reach managed endpoints and set up persistence through legitimate tunneling infrastructure, not custom malware.
Three different products, three different vendors, one pattern. The tool built to manage many environments at once is worth more to an attacker than any single environment it manages.
Identity is the primary battleground now, not endpoints
Guardz's 2026 State of MSP Threat Report, drawn from telemetry across SMB environments, found that 89 percent of monitored organizations had at least one user with a confirmed credential compromise at some point, and ransomware detections rose sharply over the same window. Flagging this as third-party research for the record, not our own figures, and worth a link to the source report on the live page.
The report's other finding matters just as much. Session hijacking is growing fastest of all, specifically because it works around multi-factor authentication rather than trying to beat it. An attacker who steals a live session does not need your password. They already have your access.
That is the same pattern behind the RMM and remote access exploits above. Nobody guessed a password. They found a gap in the authentication logic itself and walked through it.
What this means for your own stack, not just your clients'
Most MSPs run a mature monitoring program for client environments and a much lighter one for their own. The RMM console, the SD-WAN orchestrator, the remote access gateway, these sit outside the client-facing service and often outside the SOC's field of view entirely.
That is backward. Your own tooling has broader reach than any single client network. A compromised RMM admin account can touch every environment it manages in one move. Treat your own management plane as the highest value asset you operate, because to an attacker, it is exactly that.
A short audit checklist for your own tools
List every management tool with reach across client environments: RMM, PSA, SD-WAN orchestrator, remote access gateway, backup console.
Confirm each one is on a version covered by the vendor's latest advisory, not just the version you patched last quarter. Some 2026 fixes needed a second hotfix days later.
Enforce MFA on every admin account for these tools specifically, not just on the client-facing product.
Review admin activity logs for these tools on a fixed cadence, the same way you review a client's logs, not only when something looks wrong.
Know what each tool's remote access feature can reach, and segment it so a compromised console cannot touch every client at once.
Where enhanced.io fits
Correlated detection across all five surfaces, endpoint, network, cloud, identity and IoT/OT, is built to catch exactly this pattern: a management tool behaving normally on its own dashboard while its access is being abused somewhere else in the estate. Your named Fractional Security Director reviews that correlated picture and flags what a single-tool view misses. We watch identity and network activity together, because this year's attacks keep proving that neither one tells the whole story alone.
FAQ
Are MSP tools now bigger targets than client environments?
They are a primary target in their own right. RMM platforms, SD-WAN orchestrators and remote access appliances sit in front of every client you manage, so one flaw in one tool can reach hundreds of environments at once. That makes them a higher-value target than any single client network.
What should I check after an RMM or network vendor patches a CVE?
Does MFA alone stop these attacks?