CVE-2025-8875
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Aug 13, 2025
- US federal agencies must remediate it by Aug 20, 2025 (BOD 22-01)
- Attacked 2 days before the vulnerability was made public
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Source: CISA KEV · Jan 20, 2026 Nov 12, 2025 Sep 15, 2025 Sep 3, 2025 Aug 20, 2025 Aug 17, 2025
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
| Vendors | Product | Versions |
|---|---|---|
| n-able | n-central | < 2025.3.1 |
Related articles
VulnerabilitiesN‑able N‑central Under Attack: CVE‑2026‑18577 Exploited to Bypass Prior Patch
Attackers exploit N-able N-central CVE-2026-18577 to bypass authentication. Discover how to patch servers and hunt for malicious CloudFlare tunnels.
VulnerabilitiesN-able Fixes Critical Pre-Auth RCE in N-central as Exploitation Reports Conflict
N-able fixes CVE-2026-86218, a CVSS 10.0 pre-auth RCE in N-central. Update to 2026.3.1.14 immediately amid conflicting exploitation reports.
This product uses the NVD API but is not endorsed or certified by the NVD.