logo

CISA Warns of Active Exploits in N-able N-central, Urges Upgrade to 2025.3.1

ID: 6f36a97d-18d2-577e-98c8-d8b021671e7f

STIX ID: report--6f36a97d-18d2-577e-98c8-d8b021671e7f

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2025-08-14

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

CISA added two high-risk N-able N-central vulnerabilities (CVE-2025-8875 insecure deserialization and CVE-2025-8876 command injection) to its Known Exploited Vulnerabilities catalog; N-able released version 2025.3.1 to address them and urges immediate upgrade, enforcement of MFA, and monitoring via expanded audit logs, as both flaws can enable authenticated attackers to execute arbitrary code or commands and are being actively exploited.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.