Critical N-able N-central Vulnerability and Active Exploitation
Huntress, Sunday, September 6th, 2026
A critical N-central flaw gives unauthenticated attackers console-level privileges on the RMM platform.
Huntress reported a critical vulnerability in N-able N-central granting unauthenticated attackers access with console privileges, alongside evidence of active exploitation.
N-central is a remote monitoring and management platform, so console access means control over every endpoint it manages, which for a managed service provider means every customer environment. The post covers the observed exploitation and immediate mitigation guidance.
RMM platforms have been among the most consequential targets of the past several years precisely because of this concentration of privilege.