logo

Critical Vulnerability in N-able Passportal Extensions Exposed

ID: 48c2ebce-752a-5948-ae0c-098fa2e69666

STIX ID: report--48c2ebce-752a-5948-ae0c-098fa2e69666

Feed Name: ThreatCluster

Threat Score
80/100

Date Published: 2026-08-21

Date Updated: 2026-08-21

...
...

A critical vulnerability (CVE-2026-15580, CVSS 9.4) in N-able Passportal browser extensions for Chrome and Edge (v3.49.5) could allow malicious websites or iframes to access password vaults and live 2FA codes; N-able published v3.49.6 on 2026-08-21 to fix the issue and organizations are urged to update immediately to mitigate credential theft and unauthorized access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.