Web_Logo
Remote Support
Security Alert: Flaw in IT Management Tool Exploited
Home » Security Alerts  »  Security Alert: Flaw in IT Management Tool Exploited

Security Alert: Flaw in IT Management Tool Exploited

A critical security flaw in a widely used remote IT management platform is being actively exploited by attackers right now, and it's worth knowing about even if you don't manage the tool yourself.

  • What it is: A vulnerability in N-central, a platform many IT service providers use to remotely monitor and manage business computers and networks, lets an attacker gain full administrative control without needing a valid login.
  • Who is affected: Any organisation whose systems are managed through N-central, across both cloud-hosted and on-premises versions. The flaw affects all currently supported releases.
  • The risk: Successful exploitation hands an attacker "god-mode" access to the console that controls potentially thousands of managed devices, which could then be used to deploy malware or ransomware across every client on that platform.
  • What to do: The vendor has released a hotfix (version 2026.3.1.7) and is urging immediate action, along with restricting console access, enforcing multi-factor authentication, and reviewing recent account activity for anything unusual.

If your business relies on a managed IT provider, it's a reasonable question to ask which remote management platform they use and whether it's been affected. We recommend businesses treat this as a prompt to review who has administrative access to their systems and how that access is secured.

Source: Huntress advisory