[CRITICAL] "N-able N-central Pre-Auth RCE Flaw Exploited in the Wild" โ The Hacker News
criticalDetails
A critical pre-authentication remote code execution (RCE) vulnerability in N-able N-central allows unauthenticated attackers to gain complete control of affected systems. The flaw has a maximum CVSS score of 10.0.
Affected Systems
N-able N-central
Potential Impact
Compromise of N-able N-central, a remote monitoring and management (RMM) platform, could allow attackers to gain administrative access to the networks of managed service providers (MSPs) and their downstream customers, leading to widespread system compromise.
Mitigations
Apply patches immediately. CISA has mandated that Federal Civilian Executive Branch (FCEB) agencies apply fixes by September 11, 2026.