U.S. CISA adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds N-able N-Central flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added N-able N-Central flaws to its Known Exploited Vulnerabilities (KEV) catalog.

Below are the descriptions for these flaws:

  • CVE-2025-8875 N-able N-central Insecure Deserialization Vulnerability
  • CVE-2025-8876 N-able N-central Command Injection Vulnerability

N-able N-central is an Remote Monitoring and Management (RMM) platform for MSPs to centrally manage and secure Windows, Apple, and Linux endpoints.

GA of N-central 2025.3.1 address both vulnerabilities.

“This release includes a critical security fix for CVE-2025-8875 and CVE-2025-8876. These vulnerabilities require authentication to exploit.” reads the advisory. “However, there is a potential risk to the security of your N-central environment, if unpatched. You must upgrade your on-premises N-central to 2025.3.1.”

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the vulnerabilities by August 20, 2025.

Yesterday, U.S. Cybersecurity and Infrastructure Security Agency (CISA) also added Microsoft Internet Explorer, Microsoft Office Excel, and WinRAR flaws to its Known Exploited Vulnerabilities catalog.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cisa)

Leave a Reply

Your email address will not be published. Required fields are marked *

Subscribe to our Newsletter