CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2007-0671 | Remote Code Execution in Microsoft Office Excel via Crafted Spreadsheet Files CVE-2007-0671 is a remote code execution vulnerability in the Microsoft Office Excel spreadsheet engine. An attacker triggers it by persuading a user to open a specially crafted Excel file, typically delivered as an email attachment or hosted on a malicious website, corrupting Excel's file parsing and handing control to the attacker. Successful exploitation allows arbitrary code execution in the context of the logged-on user, letting the attacker install programs, view or modify data, or take over the workstation. Any user of the affected Microsoft Office/Excel versions who opens spreadsheets from untrusted sources is exposed; the source data does not specify affected version ranges, so defenders should consult Microsoft's advisory for their versions. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-12, indicating known exploitation in the wild, and carries a high EPSS score of 42.4% (99th percentile); no public proof-of-concept is known. Do: Apply the Microsoft security updates and mitigations for this CVE per vendor instructions; federal agencies must follow BOD 22-01 timelines or discontinue use if mitigations are unavailable. Until patched, do not open Excel attachments or downloaded spreadsheets from untrusted sources and warn users about spreadsheet-borne attacks. Inventory endpoints for the affected Office/Excel versions and prioritize patching high-risk and frequently emailed users. | — | 42% | KEV |
| masshundreds of millions of Office/Excel users (legacy-version subset; any endpoint opening untrusted spreadsheets) | |
| CVE-2013-3893 | Memory Corruption RCE in Microsoft Internet Explorer CVE-2013-3893 is a resource-management (memory corruption) flaw in Microsoft Internet Explorer that can allow remote code execution (CWE-399). It is triggered remotely, typically when a user views attacker-controlled web content in a vulnerable version of Internet Explorer. A successful attacker gains the ability to execute arbitrary code in the context of the current user, potentially compromising the workstation. Organizations still running Internet Explorer, which CISA notes may be end-of-life (EoL) and/or end-of-service (EoS), are affected; specific affected version ranges were not provided in the source data. The flaw was patched in Microsoft's October 2013 Patch Tuesday after being exploited in the wild (Operation DeputyDog, per related reporting), and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-12 with a very high EPSS of 85.9% (100th percentile), indicating active or imminent exploitation. Do: Apply mitigations per Microsoft's vendor instructions and follow applicable BOD 22-01 guidance for cloud services, or discontinue use of Internet Explorer if mitigations are unavailable, per CISA's required action. Verify that affected systems have the October 2013 Patch Tuesday (or later) cumulative Internet Explorer security updates installed, and audit your estate for remaining legacy IE usage. Where IE is still needed for legacy sites, migrate to Microsoft Edge with IE mode and treat in-the-wild exploitation as likely given the KEV listing and 85.9% EPSS. | — | 86% | KEV |
| masstens to hundreds of millions of legacy Windows devices historically capable of running IE; current actively used legacy IE installs unknown but plausibly in… | |
| CVE-2025-8876 +1 in the same advisory: …8875 | OS Command Injection in N-able N-central Before 2025.3.1 N-able N-central, an RMM platform widely used by managed service providers, contains an OS command injection flaw (CWE-78) caused by improper input validation (CWE-20), allowing an attacker to execute arbitrary operating-system commands on the N-central server. The flaw is reachable over the network (AV:N) and requires only low-privileged access with no user interaction, per the CVSS 4.0 vector. Successful exploitation yields high impact on confidentiality, integrity, and availability, and the 'subsequent system' impacts indicate compromise can extend beyond the N-central server itself, putting all endpoints that the affected MSP manages at risk. All N-central deployments running versions before 2025.3.1 are affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-13 following reported customer compromises, though no public proof-of-concept is known and ransomware use is unknown. Do: Upgrade N-central to version 2025.3.1 or later immediately, as the flaw is under active exploitation and CISA KEV requires federal agencies to apply vendor mitigations per BOD 22-01 or discontinue use. MSPs should check their N-central servers for signs of compromise, review accounts for anomalous or low-privileged sessions, and assume downstream managed endpoints may be at risk given the subsequent-system impact. Note that this is one of two recently patched N-central flaws being exploited in the wild, so ensure all recent hotfixes (multiple releases in recent weeks) are applied. | 9.4 | 3% | KEV |
| largeon the order of tens of thousands of N-central server deployments (each server typically manages hundreds to thousands of downstream MSP client endpoints) |
Full article513 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 14, 2025Vulnerability / Network Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
N-able N-central is a Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs), allowing customers to efficiently manage and secure their clients' Windows, Apple, and Linux endpoints from a single, unified platform.
The vulnerabilities in question are listed below -
- CVE-2025-8875 (CVSS score: N/A) - An insecure deserialization vulnerability that could lead to command execution
- CVE-2025-8876 (CVSS score: N/A) - A command injection vulnerability via improper sanitization of user input
Both shortcomings have been addressed in N-central versions 2025.3.1 and 2024.6 HF2 released on August 13, 2025. N-able is also urging customers to make sure that multi-factor authentication (MFA) is enabled, particularly for admin accounts.
"These vulnerabilities require authentication to exploit," N-able said in an alert. "However, there is a potential risk to the security of your N-central environment, if unpatched. You must upgrade your on-premises N-central to 2025.3.1."
It's currently not known how the vulnerabilities are being exploited in real-world attacks, in what context, and what is the scale of such efforts. When reached for comment, N-able shared the following statement with The Hacker News -
Two critical vulnerabilities were identified within the N-able N-central solution—which require authentication to exploit – and could allow a threat actor to elevate their privileges and maliciously use N-central if not patched. We acted quickly to release a hotfix to address these vulnerabilities, which we have communicated to all N-central customers. Our security investigations have shown evidence of this type of exploitation in a limited number of on-premises environments. We have not seen any evidence of exploitations within N-able hosted cloud environments. Our commitment to security and transparency will continue; we have reserved two CVEs (CVE-2025-8875, CVE-2025-8876) that relate to this hotfix which we will release in the coming weeks. We’ll update customers with any additional information that becomes available as our investigation continues into this matter.
In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by August 20, 2025, to secure their networks.
The development comes a day after CISA placed two-year-old security flaws affecting Microsoft Internet Explorer and Office in the KEV catalog -
- CVE-2013-3893 (CVSS score: 8.8) - A memory corruption vulnerability in Microsoft Internet Explorer that allows for remote code execution
- CVE-2007-0671 (CVSS score: 8.8) - A remote code execution vulnerability in Microsoft Office Excel that can be exploited when a specially crafted Excel file is opened to achieve remote code execution
FCEB agencies have time till September 9, 2025, to update to the latest versions, or discontinue their use if the product has reached end-of-life (EoL) status, as is the case with Internet Explorer.
(The story was updated after publication to include a response from N-able.)
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/08/cisa-adds-two-n-able-n-central-flaws-to.html