Unauthenticated RCE Vulnerability in N-able N‑central RMM Platform Triggers Fourth Hotfix in Five Weeks
What Happened – N‑able disclosed a critical unauthenticated remote‑code‑execution (RCE) flaw affecting on‑premises N‑central builds older than 2026.3.1.14. The issue has been patched in a fourth hotfix released within five weeks, and the vendor notes that the flaw may already be exploited in the wild (unconfirmed).
Why It Matters for Trust & Control Assurance
- The scenario tests the Vulnerability Management control objective – continuous discovery, timely remediation, and auditable evidence of patching.
- A robust control‑assurance program would have already surfaced the missing patch, logged remediation steps, and provided defensible evidence for auditors.
- Verisq’s Control Mapping capability lets you map this RCE fix to the underlying control objective and capture the remediation artefacts in a single, reusable audit trail.
Who Is Affected – Managed Service Providers (MSPs) and other organisations that run N‑central for remote monitoring and management of client environments.
Recommended Actions – Deploy Hotfix 4 immediately on all affected N‑central servers, verify the patch level, update your vulnerability‑management inventory, and record remediation evidence in your continuous‑control repository.
Technical Notes – The flaw is unauthenticated, allowing an attacker to execute arbitrary code on the RMM server. No CVE identifier was disclosed in the notice; the vendor’s advisory cites a “wild‑exploitation” possibility. Source: The Hacker News