important · Edge — RMM
An unauthenticated caller can execute code on an N-central RMM server before login.
Affects
N-able N-central, remote monitoring and management servers used by MSPs to administer customer endpoints.
Network reachability to an affected on-premises N-central server is the only established prerequisite.
Detail and 2 sources
Compromise lands beside N-central's script, deployment, and remote-session functions, but public evidence does not show whether attackers used them against managed endpoints.
Chain to watch
Reach an affected N-central server before authentication.→↓Execute code on the RMM server.→↓Potentially reach managed endpoints through N-central control functions.→↓We do not know the execution identity, root cause, or whether observed exploitation reached downstream endpoints.
Unverified chainObtain a root-cause advisory or incident trace connecting server compromise to a process identity and managed-endpoint actions.