For most organisations, BOD 26-04's three-day tiers are a planning exercise. For managed service providers running N-able N-central, the clock has already gone off twice in five weeks.
The sequence
Date | What happened |
|---|---|
31 July 2026 | Exploitation of CVE-2026-18577, an N-central authentication bypass (CVSS 8.2), begins in the wild |
3 August | CVE-2026-18577 added to KEV with a 6 August deadline. 28.6% of observed self-hosted N-central servers still vulnerable and exposed |
4 August | CVE-2026-18556, the flaw 18577 was an incomplete fix for, added to KEV |
8 September | CVE-2026-86218, a pre-authentication remote code execution flaw rated CVSS 10, added to KEV with an 11 September deadline |
Fix | N-central 2026.3 Hotfix 4 addresses CVE-2026-86218 and also covers CVE-2026-18577 |
Why the RMM console is the asset that matters
An RMM platform is the system an MSP uses to run everyone else's estate. A flaw that gives total control of the console gives an attacker a route into every customer it manages. In BOD 26-04 terms, it is publicly exposed, in KEV, automatable and total control: the Tier 1 profile.

One console, many estates. Total control of the RMM is total control of the customer base.
Patching is not the whole job
Tier 1 adds a step most teams have not resourced: forensic triage. You patch within three days and establish that you were not already compromised. N-central shows why that matters. Exploitation of CVE-2026-18577 started before the advisory, so a clean patch on day two says nothing about day minus two.
In plain language
If your RMM was exposed during the exploitation window, patching closes the door. It does not tell you whether anyone walked through it first. Tier 1 asks you to find out.
How it reaches MSPs
BOD 26-04 binds federal civilian agencies, not their suppliers. But MSPs that run agency systems, or sit under a prime that flows KEV requirements down, will be asked for the same evidence: which assets were exposed, when they were fixed, and what triage showed. From December, that request becomes routine.
There is an insurance angle too. Cyber policies that define cover by reference to "known vulnerabilities" can now turn on a KEV listing date. Knowing exactly when each flaw entered KEV, and when you fixed it, is part of protecting a claim.
Three things to do now
Inventory exposure. Which RMM, remote access and management interfaces are reachable from the internet today.
Keep the timeline. KEV date, patch date and triage result for every Tier 1 and Tier 2 finding.
Rehearse triage. Agree in advance what "not already compromised" means and what evidence proves it.
Next step. The BOD 26-04 briefing pack covers the tiers, the clock and how the directive reaches contractors and MSPs. Get the briefing pack →
For any comments or information please reach out to info@astragar.com







