The N-central Exploits Are an MSP Vendor-Risk Test 0 ▲ CybersecKyle 8 hours ago · 13 min read2683 words · Tech · hide · 0 comments N-able has released four N-central hotfixes in five weeks.The latest, N-central 2026.3 Hotfix 4, fixes CVE-2026-86218: a pre-authentication remote code execution vulnerability rated 10.0 under CVSS 4.0. N-able says every version before build 2026.3.1.14 is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 8.For an ordinary business application, that would already demand an emergency response. N-central is not an ordinary business application. It is a remote monitoring and management platform that MSPs use to run scripts, open remote sessions, deploy software, and administer systems across many customers.Compromise the management plane and the attacker does not have to break into every client separately. The trusted tool can carry the attack for them.If you run N-central on-premises, the immediate job is clear: upgrade to 2026.3.1.14, reduce who can reach the console, preserve the available logs, and investigate whether someone arrived before the… No comments yet. Log in to reply on the Fediverse. Comments will appear here.