Mathspace breach exposes data on over a million students and parents
2026-09-08T08:51:40Z•c86c2ecc671243af8006f4044cdcd0e0e772b2d574a338dd0c3695fcbb0426b9
CVE-2026-86218JellyfinMetabaseMikroTik RouterOSMikroTrickN-able N-centralScreenConnectactive exploitationdata breacheducation technologymalware distributionnetwork device takeoverransomwareremote code executionunauthenticated accessvulnerability managementzero-day
What happened
Security news covering a major Mathspace data breach via an unpatched self-hosted Metabase vulnerability, Jellyfin security fixes, active exploitation of MikroTik RouterOS flaws and N-able N-central CVE-2026-86218, plus a ScreenConnect file-transfer flaw being abused to distribute malware. The most urgent items are the actively exploited pre-authentication remote code execution in N-central and unauthenticated RouterOS device takeover when internet-exposed SSH is enabled.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- c86c2ecc671243af8006f4044cdcd0e0e772b2d574a338dd0c3695fcbb0426b9
- Enrichment time
- 2026-09-08T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.