logo

Over 800 N-able servers left unpatched against critical flaws

ID: 07d85985-e1dd-547e-8194-fb990d1ef72d

STIX ID: report--07d85985-e1dd-547e-8194-fb990d1ef72d

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-08-18

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Two critical vulnerabilities in N-able N-central (CVE-2025-8875 and CVE-2025-8876) are being actively exploited; N-able released patch 2025.3.1 and CISA has mandated rapid patching for federal agencies. Shadowserver and Shodan telemetry show hundreds to thousands of exposed instances (about 880 vulnerable per Shadowserver, ~2,000 exposed per Shodan), creating significant risk to MSPs and their customers if on-prem servers remain unpatched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.