Critical Enterprise and IoT Appliances Require Immediate Patching
N-able N-central remains exposed to a pre-authentication CVSS 10 RCE requiring Hotfix 4, while Cisco Secure Email Gateway and Secure Email and Web Manager contain multiple CVSS 9.8 flaws, including an actively exploited SQL-injection issue with no effective workaround. TP-Link Tapo C200 flaws add authentication bypass, recording exposure, and lateral-movement risk; fixed firmware, asset inventory, and network segmentation should be verified.
Sources (2)
Updated Sep 16, 2026