ZeroHour

CVE-2025-8875

KEVlarge1

Insecure Deserialization Code Execution in N-able N-central (KEV)

CISA: N-able N-Central Insecure Deserialization Vulnerability

CVSS 4.0
9.4 critical
EPSS
2%p76
Published
()
KEV added
AI analysis

CVE-2025-8875 is a deserialization of untrusted data flaw (CWE-502) in N-able's N-central remote monitoring and management (RMM) platform, which runs on servers used by managed service providers to administer customer environments. An attacker can trigger it by getting the product to process crafted serialized data; the CVSS 4.0 vector indicates the attack is network-adjacent/over the network (AV:N) with only low privileges required (PR:L) and no user interaction. Successful exploitation yields code execution on the N-central server with high impact to confidentiality, integrity, and availability, giving attackers a foothold in a system that typically holds credentials and connectivity to many downstream customer networks. Any organization running an N-central release before 2025.3.1 is affected, primarily MSPs and the end customers they manage. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-13 after reported customer compromises, with EPSS estimating a 1.7% chance of exploitation within 30 days; no public proof-of-concept is known.

What to do: Upgrade N-central to 2025.3.1 or later and apply the vendor's latest hotfix (N-able has shipped a series of hotfixes for N-central flaws, including this one and the related CVE-2025-8876). As a CISA KEV entry, federal agencies must apply vendor mitigations per BOD 22-01 timelines or discontinue use if patching is unavailable. Given confirmed customer compromises, MSPs should also review N-central server logs for signs of exploitation, restrict internet exposure of the N-central interface, and rotate credentials stored in or accessible from the platform.

Affected
N-able N-centralall versions before 2025.3.1
Estimated exposure
largeon the order of tens of thousands of N-central server deployments worldwide (thousands visibly internet-exposed in public scans), indirectly reaching millions… — N-central is one of the most widely deployed MSP RMM platforms, with public internet-exposure scans showing thousands of exposed instances and each server typically managing hundreds to thousands of downstream endpoints, so the direct…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

CISA Known Exploited Vulnerability
Affected
N-able N-Central
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
n-able
Products
n-central
Weakness
CWE-502
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able shipped Hotfix 4 for a CVSS 10.0 unauthenticated RCE (CVE-2026-86218) in N-central RMM, with conflicting statements on exploitation.

N-able released 2026.3 Hotfix 4 (build 2026.3.1.14) fixing CVE-2026-86218, a static code injection weakness (CWE-96) scored 10.0 on CVSS 4.0 that enables pre-authentication remote code execution on on-premises N-central RMM servers. Hosted NCOD instances are already patched; N-able's incident notice says the flaw was observed exploited in the wild while its release notes say exploitation is unconfirmed. Huntress, which has tracked N-central attacks since August, advises IP allowlisting, VPN-only access, or taking internet-reachable servers offline until patching. It is the fourth hotfix in five weeks, following fixes for CVE-2026-86206 and CVE-2026-86207, which CISA added to its Known Exploited Vulnerabilities catalog.

The Hacker News · 8d agoVulnerability in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+4 CVEs