Critical Vulnerability in N-able Passportal Extensions Exposed
ID: 48c2ebce-752a-5948-ae0c-098fa2e69666
STIX ID: report--48c2ebce-752a-5948-ae0c-098fa2e69666
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-15580, CVSS 9.4) in N-able Passportal browser extensions for Chrome and Edge (v3.49.5) could allow malicious websites or iframes to access password vaults and live 2FA codes; N-able published v3.49.6 on 2026-08-21 to fix the issue and organizations are urged to update immediately to mitigate credential theft and unauthorized access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
