Skip to finding
important · RCE — RMM

Attackers are exploiting pre-authentication code injection in self-hosted N-central servers.

Affects

N-able N-central, remote-monitoring and management server software used by managed-service providers to administer downstream endpoints.

Network access to the server is enough to reach code execution, and control of the RMM plane can extend to managed systems where its permissions allow.

Detail and 3 sources

Huntress observed a compromised N-central environment but could not tie that incident to this exact flaw after the relevant logs rotated.

N-able says all earlier releases are affected and provides fixed releases.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026