Threat Brief — 2026-09-07 — RMM Platforms Under Active Attack
Executive summary. Two remote-access vendors are in the spotlight today: N-able has issued its fourth N-central hotfix in five weeks for an unauthenticated RCE flaw, with conflicting statements about in-the-wild exploitation. Separately, ConnectWise has disclosed a new ScreenConnect vulnerability that remains unpatched, with only temporary mitigations available. Both target RMM/remote-access infrastructure — precisely the class of product attackers prioritise for lateral movement.
Top items
- N-able N-central: fourth hotfix in five weeks for unauthenticated RCE. Every on-premises N-central build below 2026.3.1.14 — including servers patched with Hotfix 3 just a day earlier — requires Hotfix 4. N-able's incident notice states the flaw has been exploited in the wild, though the release notes contradict this, calling exploitation unconfirmed. This is a developing story first reported today. (src: The Hacker News) (src: BleepingComputer)*
- ConnectWise warns of new ScreenConnect vulnerability with no patch available. ConnectWise has published temporary mitigation measures for a newly disclosed ScreenConnect remote-access vulnerability; a patch is expected later this week. No exploit evidence has been reported, but the disclosure of an unpatched flaw in a widely deployed remote-access product creates an immediate exposure window. (src: BleepingComputer)
Themes
RMM and remote-access tooling remains a primary target. Both items concern platforms that provide privileged remote access to large fleets of endpoints. Attackers prioritise these because a single compromise yields broad downstream access. The N-able situation is further complicated by a rapid succession of hotfixes — four in five weeks — suggesting either an evolving vulnerability landscape or incomplete initial remediation. The ConnectWise disclosure adds a second unpatched exposure surface for organisations reliant on remote-support tooling. In both cases, the mitigations are partial and the patches are either not yet available (ScreenConnect) or have required repeated iteration (N-central).
===
THREAT-TOPICS===
[{"slug":"nable-n-central-rce-flaw-active-attacks","headline":"N-able issues fourth N-central hotfix in five weeks for unauthenticated RCE","findingIds":[11253,11242],"status":"developing","development":"Fourth hotfix released; all builds below 2026.3.1.14 affected, including those patched with Hotfix 3 a day earlier; vendor incident notice says exploited in the wild while release notes say unconfirmed."},{"slug":"connectwise-screenconnect-new-flaw-no-patch","headline":"ConnectWise discloses new ScreenConnect vulnerability without patch","findingIds":[11252],"status":"new"}]
