Safeguard
Vulnerability Analysis

ConnectWise ScreenConnect, SimpleHelp and N-able N-central: Remote Access Tools Keep Entering KEV

Four vulnerabilities across three remote monitoring and management platforms confirmed as exploited between June and September 2026. RMM software's structural appeal to ransomware operators, explained through the actual mechanisms.

Safeguard Research Team
4 min read

Remote monitoring and management software — the tools IT teams and managed service providers use to reach into a machine they administer — put four vulnerabilities into CISA's Known Exploited Vulnerabilities catalogue between late June and mid-September 2026, across three products.

CVEProductCVSSAdded to KEV
CVE-2026-48558SimpleHelp10.029 Jun 2026
CVE-2026-84869ConnectWise ScreenConnect9.911 Sep 2026
CVE-2026-86218N-able N-central9.88 Sep 2026
CVE-2026-18556N-able N-central7.44 Aug 2026

This is not a new pattern for the category — RMM software has been a preferred ransomware entry point for years, precisely because its entire purpose is remote, privileged access to endpoints, and it is usually allow-listed through security tooling that would otherwise flag a remote-access tool as suspicious. What is worth reading closely is how each of these four bypasses the layer meant to stop exactly that.

Three different doors, one destination

CVE-2026-48558, CVSS 10.0, is an authentication bypass in SimpleHelp's OIDC flow. Per NVD, it affects versions 5.5.15 and earlier plus 6.0 pre-release builds, and it applies specifically when OIDC authentication is configured — meaning the deployments most likely to consider themselves hardened, because they took the extra step of wiring in single sign-on, are the ones exposed.

CVE-2026-84869 is more subtle: a condition in the ScreenConnect client that can allow files to be transferred and executed through an already active remote session without authorization or host confirmation. This is not a way in — it is a way to do more once a legitimate session exists, which matters because the legitimate session is the thing every RMM security model assumes is the trust boundary.

N-able N-central's pair covers both ends: CVE-2026-18556 is an authentication bypass using an alternate path, and CVE-2026-86218, added a month later, is pre-authentication remote code execution. Read together, an attacker with the first CVE could reasonably be assumed to be probing for exactly the second.

Why RMM compromise is worse than ordinary server compromise

An RMM platform's job is to be trusted by everything it touches. A single compromised instance — SimpleHelp, ScreenConnect, or an N-central server — typically has standing, authenticated, often unsupervised access to every endpoint it manages. For a managed service provider, that is every client's environment behind one login.

This is also why RMM tools are consistently a top initial-access vector in ransomware investigations industry-wide: the access an attacker gains is not a foothold to be escalated. It is already the administrative reach a ransomware operator wants, delivered by the software the target organisation installed and trusts on purpose.

Why the OIDC-specific condition on the SimpleHelp bug matters

CVE-2026-48558 applying specifically "when OIDC authentication is configured" is a detail worth sitting with rather than skimming past. Organisations that took the additional step of integrating SimpleHelp with a corporate identity provider generally did so precisely because they wanted stronger authentication than the platform's default local accounts provide — audit logging, centralised revocation, multi-factor enforcement inherited from the identity provider. This bug means that specific hardening step introduced the vulnerable code path rather than closing it, which inverts the intuition an administrator would reasonably have going in: the more security-conscious configuration is the one this CVE affects.

What to check this week

Confirm whether OIDC is configured on any SimpleHelp instance you run, and patch past 5.5.15 regardless — CVE-2026-48558's CVSS 10.0 reflects an unauthenticated path to full access.

Review what "an active session" is allowed to do on ScreenConnect, not just who can start one. CVE-2026-84869 exploits the assumption that a session, once open, is safe to trust completely.

Treat N-central's two CVEs as one incident, not two tickets. An alternate-path authentication bypass followed a month later by pre-auth RCE in the same product is the shape of a vulnerability class being worked, not two unrelated bugs.

Ask what your RMM tooling is allowed to reach that nothing else is. If the answer is "everything," the blast radius of any one of these four CVEs is your entire managed fleet, not one instance.

How Safeguard helps

Safeguard's continuous inventory covers the management and remote-access tooling in an environment alongside application dependencies, so an RMM platform's version and exposure are tracked with the same rigor as a library in a build manifest — not discovered for the first time when a CVE like this one makes the news. Reachability analysis then answers the question that actually decides urgency for a class of software built to be trusted everywhere: not whether the vulnerable version is present, but what it can reach if it is exploited.

Never miss an update

Weekly insights on software supply chain security, delivered to your inbox.

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.