CuraSec

Act active

N-able N-central RCE Hotfix 4 — Possible Active Exploitation

2026-09-07 16:27 UTC · The Hacker News · read the source ↗ #rmm#unauthenticated-rce#active-exploitation
  • Engineer — Act: Unauthenticated RCE on an RMM platform with a credible (if contradictory) exploitation-in-the-wild claim — highest-priority patch category. Upgrade every on-premises N-central instance to 2026.3.1.14 (Hotfix 4) immediately; servers patched to Hotfix 3 yesterday are still vulnerable.
  • SOC/IR — Act: Compromised RMM infrastructure gives attackers admin reach across all managed endpoints — an assume-breach posture is warranted. Hunt for anomalous outbound connections or command execution originating from N-central servers since the Hotfix 3 deployment date, and monitor for lateral movement from MSP-managed jump hosts.
  • Leader — Act: If your organization uses an MSP that runs N-central, contact them this week to confirm Hotfix 4 is applied and request evidence of no compromise; RMM breaches are a proven ransomware delivery path. The conflicting exploitation signals from N-able’s own communications (incident notice vs. release notes) also warrant asking for a formal vendor statement.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.