This day 02:08 06:08 10:09 14:10 18:01 22:01
Info  2026-09-07 10:09Z · last 4h · 19 findings · glm-5.2:cloud

Threat Brief — 2026-09-07 — RMM Platforms Under Active Attack

Executive summary. Two remote-access vendors are in the spotlight today: N-able has issued its fourth N-central hotfix in five weeks for an unauthenticated RCE flaw, with conflicting statements about in-the-wild exploitation. Separately, ConnectWise has disclosed a new ScreenConnect vulnerability that remains unpatched, with only temporary mitigations available. Both target RMM/remote-access infrastructure — precisely the class of product attackers prioritise for lateral movement.

Top items

Themes

RMM and remote-access tooling remains a primary target. Both items concern platforms that provide privileged remote access to large fleets of endpoints. Attackers prioritise these because a single compromise yields broad downstream access. The N-able situation is further complicated by a rapid succession of hotfixes — four in five weeks — suggesting either an evolving vulnerability landscape or incomplete initial remediation. The ConnectWise disclosure adds a second unpatched exposure surface for organisations reliant on remote-support tooling. In both cases, the mitigations are partial and the patches are either not yet available (ScreenConnect) or have required repeated iteration (N-central).

===

THREAT-TOPICS===

[{"slug":"nable-n-central-rce-flaw-active-attacks","headline":"N-able issues fourth N-central hotfix in five weeks for unauthenticated RCE","findingIds":[11253,11242],"status":"developing","development":"Fourth hotfix released; all builds below 2026.3.1.14 affected, including those patched with Hotfix 3 a day earlier; vendor incident notice says exploited in the wild while release notes say unconfirmed."},{"slug":"connectwise-screenconnect-new-flaw-no-patch","headline":"ConnectWise discloses new ScreenConnect vulnerability without patch","findingIds":[11252],"status":"new"}]

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db