logo

CISA Warns N-able Bugs Under Attack, Patch Now

ID: a38cba00-1038-592b-bfd8-40ab0129c0ff

STIX ID: report--a38cba00-1038-592b-bfd8-40ab0129c0ff

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-08-14

Date Updated: 2026-04-21

Author: Alexander Culafi

...
...

CISA added two critical N‑able N‑central vulnerabilities (CVE‑2025‑8875 and CVE‑2025‑8876) to its Known Exploited Vulnerabilities catalog after reports of limited active exploitation; one is a deserialization flaw (CVSS 9.4) and the other allows OS command injection. Both require authentication, affect on‑premises N‑central versions prior to 2025.3.1, and N‑able has released a hotfix/upgrade to 2025.3.1 with customers and federal agencies urged to remediate promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.