Skip to finding
important · Edge — RMM

An unauthenticated caller can execute code on an N-central RMM server before login.

Affects

N-able N-central, remote monitoring and management servers used by MSPs to administer customer endpoints.

Network reachability to an affected on-premises N-central server is the only established prerequisite.

Detail and 2 sources

Compromise lands beside N-central's script, deployment, and remote-session functions, but public evidence does not show whether attackers used them against managed endpoints.

Chain to watch
Reach an affected N-central server before authentication.→↓Execute code on the RMM server.→↓Potentially reach managed endpoints through N-central control functions.→↓We do not know the execution identity, root cause, or whether observed exploitation reached downstream endpoints.
Unverified chainObtain a root-cause advisory or incident trace connecting server compromise to a process identity and managed-endpoint actions.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 10, 2026