important · RCE — RMM
Attackers are exploiting pre-authentication code injection in self-hosted N-central servers.
Affects
N-able N-central, remote-monitoring and management server software used by managed-service providers to administer downstream endpoints.
Network access to the server is enough to reach code execution, and control of the RMM plane can extend to managed systems where its permissions allow.
Detail and 3 sources
Huntress observed a compromised N-central environment but could not tie that incident to this exact flaw after the relevant logs rotated.
N-able says all earlier releases are affected and provides fixed releases.