ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-8875CVE-2025-8876

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-8876
+1 in the same advisory: …8875
OS Command Injection in N-able N-central Before 2025.3.1

N-able N-central, an RMM platform widely used by managed service providers, contains an OS command injection flaw (CWE-78) caused by improper input validation (CWE-20), allowing an attacker to execute arbitrary operating-system commands on the N-central server. The flaw is reachable over the network (AV:N) and requires only low-privileged access with no user interaction, per the CVSS 4.0 vector. Successful exploitation yields high impact on confidentiality, integrity, and availability, and the 'subsequent system' impacts indicate compromise can extend beyond the N-central server itself, putting all endpoints that the affected MSP manages at risk. All N-central deployments running versions before 2025.3.1 are affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-08-13 following reported customer compromises, though no public proof-of-concept is known and ransomware use is unknown.

Do: Upgrade N-central to version 2025.3.1 or later immediately, as the flaw is under active exploitation and CISA KEV requires federal agencies to apply vendor mitigations per BOD 22-01 or discontinue use. MSPs should check their N-central servers for signs of compromise, review accounts for anomalous or low-privileged sessions, and assume downstream managed endpoints may be at risk given the subsequent-system impact. Note that this is one of two recently patched N-central flaws being exploited in the wild, so ensure all recent hotfixes (multiple releases in recent weeks) are applied.

9.43% KEV
  • N-able N-central all versions before 2025.3.1
largeon the order of tens of thousands of N-central server deployments (each server typically manages hundreds to thousands of downstream MSP client endpoints)
Full article239 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added N-able N-Central flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-8875 N-able N-central Insecure Deserialization Vulnerability
  • CVE-2025-8876 N-able N-central Command Injection Vulnerability

N-able N-central is an Remote Monitoring and Management (RMM) platform for MSPs to centrally manage and secure Windows, Apple, and Linux endpoints.

GA of N-central 2025.3.1 address both vulnerabilities.

“This release includes a critical security fix for CVE-2025-8875 and CVE-2025-8876. These vulnerabilities require authentication to exploit.” reads the advisory. “However, there is a potential risk to the security of your N-central environment, if unpatched. You must upgrade your on-premises N-central to 2025.3.1.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by August 20, 2025.

Yesterday, U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalog.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cisa)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181135/security/u-s-cisa-adds-n-able-n-central-flaws-to-its-known-exploited-vulnerabilities-catalog.html