ZeroHour

CVE-2025-8876

KEVlarge

OS Command Injection in N-able N-central Before 2025.3.1

CISA: N-able N-Central Command Injection Vulnerability

CVSS 4.0
9.4 critical
EPSS
3%p88
Published
()
KEV added
AI analysis

N-able N-central, an RMM platform widely used by managed service providers, contains an OS command injection flaw (CWE-78) caused by improper input validation (CWE-20), allowing an attacker to execute arbitrary operating-system commands on the N-central server. The flaw is reachable over the network (AV:N) and requires only low-privileged access with no user interaction, per the CVSS 4.0 vector. Successful exploitation yields high impact on confidentiality, integrity, and availability, and the 'subsequent system' impacts indicate compromise can extend beyond the N-central server itself, putting all endpoints that the affected MSP manages at risk. All N-central deployments running versions before 2025.3.1 are affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-13 following reported customer compromises, though no public proof-of-concept is known and ransomware use is unknown.

What to do: Upgrade N-central to version 2025.3.1 or later immediately, as the flaw is under active exploitation and CISA KEV requires federal agencies to apply vendor mitigations per BOD 22-01 or discontinue use. MSPs should check their N-central servers for signs of compromise, review accounts for anomalous or low-privileged sessions, and assume downstream managed endpoints may be at risk given the subsequent-system impact. Note that this is one of two recently patched N-central flaws being exploited in the wild, so ensure all recent hotfixes (multiple releases in recent weeks) are applied.

Affected
N-able N-centralall versions before 2025.3.1
Estimated exposure
largeon the order of tens of thousands of N-central server deployments (each server typically manages hundreds to thousands of downstream MSP client endpoints) — N-central is one of the most widely deployed MSP RMM platforms, with public reporting and vendor positioning indicating a large installed base of management servers whose compromise cascades to millions of managed endpoints; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

CISA Known Exploited Vulnerability
Affected
N-able N-Central
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
n-able
Products
n-central
Weakness
CWE-20, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able shipped Hotfix 4 for a CVSS 10.0 unauthenticated RCE (CVE-2026-86218) in N-central RMM, with conflicting statements on exploitation.

N-able released 2026.3 Hotfix 4 (build 2026.3.1.14) fixing CVE-2026-86218, a static code injection weakness (CWE-96) scored 10.0 on CVSS 4.0 that enables pre-authentication remote code execution on on-premises N-central RMM servers. Hosted NCOD instances are already patched; N-able's incident notice says the flaw was observed exploited in the wild while its release notes say exploitation is unconfirmed. Huntress, which has tracked N-central attacks since August, advises IP allowlisting, VPN-only access, or taking internet-reachable servers offline until patching. It is the fourth hotfix in five weeks, following fixes for CVE-2026-86206 and CVE-2026-86207, which CISA added to its Known Exploited Vulnerabilities catalog.

The Hacker News · 8d agoVulnerability in the wildCVE-2026-86218CVE-2026-86206CVE-2026-86207+4 CVEs