The Maivia Gazette

Verified AI news, every morning

Security

N-able ships emergency N-central fix as ConnectWise warns of unpatched ScreenConnect bug

Two widely used IT management platforms disclosed serious flaws over the weekend, one rated maximum severity and one still awaiting a patch.

A view from a watchtower window, partly boarded with new planks, over a valley of small houses connected by cables.
AI-generated illustration, not event photography.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

Two remote management platforms used by managed service providers disclosed security problems within days of each other. N-able released N-central 2026.3 Hotfix 4 on Saturday to close CVE-2026-86218, a maximum-severity remote code execution flaw. The bug lets unprivileged attackers run malicious code on unpatched N-central instances exposed online in low-complexity attacks. "At this time, we have no confirmations that this vulnerability has been exploited in production environments, but unpatched systems remain at risk," the company said, urging on-premises customers to upgrade immediately. Security firm Huntress has flagged the flaw as a potential zero-day. Shadowserver counts nearly 1,500 N-central servers exposed online, most in the United States and Europe. The Hacker News reports this is the fourth N-central hotfix in five weeks for an unauthenticated RCE issue. Separately, ConnectWise published temporary mitigations for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. The issue affects both cloud and on-premises deployments and has no CVE ID yet. ConnectWise described it as "an issue affecting file transfer behavior" in Remote Access Support and Access sessions. Until a fix ships, administrators are advised to open the Roles page under Security in the ScreenConnect administration console and remove the TransferFiles permission, or TransferFilesInSession for legacy setups, from every session group in every role. Shadowserver tracks nearly 6,000 ScreenConnect instances online.

Sources

  1. BleepingComputerN-able patches max severity N-central flaw amid ongoing attacksPublished · fetched
  2. The Hacker NewsN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE FlawPublished · fetched
  3. BleepingComputerConnectWise warns of new ScreenConnect flaw without patchPublished · fetched

Also in this edition