N-able’s N-central, the remote monitoring and management (RMM) platform managed service providers use to oversee thousands of client networks from one console, disclosed a pre-authentication remote code execution flaw carrying a maximum CVSS score of 10.0 — its second critical, actively exploited incident in six weeks. Almost as urgently, Cisco confirmed that a single crafted email can hand an unauthenticated attacker root access on Secure Email Gateway, a flaw rated CVSS 9.8 with a federal patch deadline landing today.