SEKurity GmbH Logo

#MSP

1 Article tagged

[*] Filtering articles by tag: MSP
[+] Matching entries: 1
root@sekurity:~# ls -la /tags/msp/* _

CVE Research
sekurity-team

InSEKurity of the Week (CW37/2026): N-able N-central Pre-Auth RCE via Struts BeanUtils Race (CVE-2026-86218)

Two concurrent multipart requests to an unauthenticated Struts action hand an attacker Jetty's live configuration, and from there a root-adjacent shell on the box that manages every endpoint an MSP touches. CVSS 10.0, exploited before disclosure, in CISA KEV on September 8 -- the fourth N-central hotfix in five weeks.

01

root@sekurity:~# echo "End of results for tag: MSP"
End of results for tag: MSP
root@sekurity:~# _