Mathspace breach exposes data on over a million students and parents

2026-09-08T08:51:40Zc86c2ecc671243af8006f4044cdcd0e0e772b2d574a338dd0c3695fcbb0426b9
CVE-2026-86218JellyfinMetabaseMikroTik RouterOSMikroTrickN-able N-centralScreenConnectactive exploitationdata breacheducation technologymalware distributionnetwork device takeoverransomwareremote code executionunauthenticated accessvulnerability managementzero-day

What happened

Security news covering a major Mathspace data breach via an unpatched self-hosted Metabase vulnerability, Jellyfin security fixes, active exploitation of MikroTik RouterOS flaws and N-able N-central CVE-2026-86218, plus a ScreenConnect file-transfer flaw being abused to distribute malware. The most urgent items are the actively exploited pre-authentication remote code execution in N-central and unauthenticated RouterOS device takeover when internet-exposed SSH is enabled.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
c86c2ecc671243af8006f4044cdcd0e0e772b2d574a338dd0c3695fcbb0426b9
Enrichment time
2026-09-08T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Mathspace breach exposes data on over a million students and parents · Baitaphish