By Interestana AI Editorial — AI-drafted, human-overseen. How we report
N-able Releases Fourth N-central Hotfix for RCE Flaw

N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, specifically addressing an unauthenticated remote code execution (RCE) vulnerability. This latest update, Hotfix 4, is designated for all on-premises N-central builds prior to version 2026.3.1.14. This includes servers that had been updated to Hotfix 3 just one day before the release of Hotfix 4. The company's incident notice indicates that the vulnerability has been exploited in the wild, although the release notes state this exploitation is currently unconfirmed. The urgency of these frequent updates highlights the critical nature of the security issues being addressed within the N-central platform, which is a key tool for managed service providers (MSPs) to remotely manage and monitor their clients' IT infrastructure.
The N-central platform is designed to provide comprehensive IT management capabilities, including device monitoring, patch management, automation, and remote access, all crucial for MSPs delivering services to a diverse client base. The presence of an unauthenticated RCE vulnerability means that an attacker could potentially gain control of a vulnerable N-central server without needing any credentials. This level of access could allow an attacker to deploy malware, steal sensitive data, or disrupt services for all clients managed by that N-central instance. The rapid release of four hotfixes in a short period suggests a significant and persistent security challenge for N-able and its users.
N-able, a subsidiary of SolarWinds, provides IT management solutions for MSPs. The N-central platform is one of its flagship products, widely used in the MSP market. The continuous patching cycle indicates that the initial fixes may not have fully remediated the issue or that new related vulnerabilities have been discovered. This situation places a burden on MSPs to constantly update their systems to maintain security, which can be time-consuming and resource-intensive. The company's communication, noting the unconfirmed nature of in-the-wild exploitation, contrasts with the explicit mention of exploitation in the incident notice, suggesting a degree of uncertainty or evolving understanding of the threat landscape.
Users of the N-central platform are strongly advised to apply Hotfix 4 as soon as possible to mitigate the risks associated with this unauthenticated RCE flaw. The continuous stream of security updates underscores the importance of proactive patch management for RMM solutions, as these platforms often hold privileged access to numerous client environments. The ongoing security efforts by N-able aim to protect both their own infrastructure and the vast networks managed by their MSP customers from potential cyber threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.