Skip to content
Threat Feed

Vendor

N-Able

9 briefs RSS
critical threat

Critical RCE Vulnerability in N-able N-central

A critical unauthenticated remote code execution vulnerability (CVE-2026-86218) in N-able N-central is under active exploitation, allowing attackers to gain full system control.

N-central +2 vulnerability rce critical remote-management
1t updated
high advisory

Exploitation of N-able N-central via CVE-2024-27429

Threat actors are exploiting a remote code execution vulnerability (CVE-2024-27429) in N-able N-central to gain unauthorized access and deploy RMM payloads on managed systems.

N-central remote-code-execution rmm supply-chain
3t 1c
medium advisory

Detection of Novel RMM Software Usage

This brief details a detection strategy for identifying the introduction of remote monitoring and management (RMM) software in Windows environments by monitoring for newly observed code-signing certificates.

RMM Software rmm command-and-control windows endpoint-detection
1r 1t
high advisory

N-able N-central Authentication Bypass Exploitation

Threat actors are actively exploiting a patch bypass vulnerability (CVE-2026-18577) in N-able N-central to gain administrative control and establish persistent remote access via Cloudflare tunnels.

PoC N-central +3 supply-chain rmm cve-2026-18577 exploitation
3t 2c 6i updated
critical advisory

IBM Langflow OSS Unauthenticated Remote Code Execution via Chained API Endpoints (CVE-2026-9198)

Unauthenticated attackers can achieve Remote Code Execution (RCE) on default IBM Langflow OSS deployments, versions 1.0.0 through 1.10.0, by chaining access to the `/api/v1/auto_login` endpoint, which mints SUPERUSER tokens, with the `/api/v1/validate/code` endpoint, which executes user-supplied code via `exec()`.

Langflow OSS +10 remote-code-execution api-exploitation unauthenticated-access code-injection web-vulnerability ai-llm
1r 3t 11c 2i updated
medium advisory

Suspicious DNS Queries to Remote Monitoring and Management Domains from Non-Browser Processes

This brief details the detection of DNS queries targeting commonly abused Remote Monitoring and Management (RMM) or remote access software domains, originating from non-browser processes, which is a common tactic for command and control, persistence, and lateral movement by threat actors.

01com +151 windows command-and-control endpoint rmm remote-access
1r 193i
medium advisory

PowerShell Script Block Logging Disabled via Registry Modification

Attackers may disable PowerShell Script Block Logging by modifying the registry to conceal their activities on the host and evade detection by setting the `EnableScriptBlockLogging` registry value to 0, impacting security monitoring and incident response capabilities.

Defender XDR +2 defense-evasion powershell registry
2r 2t
medium advisory

Suspicious DNS Queries to RMM Domains from Non-Browser Processes

Detection of DNS queries to remote monitoring and management (RMM) domains from non-browser processes indicating potential misuse of legitimate remote access tools for command and control.

Elastic Endpoint +1 command-and-control remote-access windows
2r
medium advisory

Detection of Windows RMM Tool Execution

Detects process creation events indicative of remote management tools, potentially signifying legitimate use or malicious exploitation by threat actors abusing RMM software.

AnyDesk +28 rmm remote-access sysmon
3r 1t