CISA Warns N-able Bugs Under Attack, Patch Now
ID: a38cba00-1038-592b-bfd8-40ab0129c0ff
STIX ID: report--a38cba00-1038-592b-bfd8-40ab0129c0ff
Feed Name: Dark Reading
Threat Score
CISA added two critical N‑able N‑central vulnerabilities (CVE‑2025‑8875 and CVE‑2025‑8876) to its Known Exploited Vulnerabilities catalog after reports of limited active exploitation; one is a deserialization flaw (CVSS 9.4) and the other allows OS command injection. Both require authentication, affect on‑premises N‑central versions prior to 2025.3.1, and N‑able has released a hotfix/upgrade to 2025.3.1 with customers and federal agencies urged to remediate promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
