CISA warned on Wednesday that attackers are actively exploiting two security vulnerabilities in N‑able's N-central remote monitoring and management (RMM) platform. N-central is commonly used by managed services providers (MSPs) and IT departments to monitor, manage, and maintain client networks and devices from a centralized web-based console. According to CISA, the two flaws can allow authenticated attackers to gain command execution via an insecure deserialization weakness (CVE-2025-8875) and inject commands by exploiting an improper sanitization of user input vulnerability (CVE-2025-8876). N-able confirms CISA's report that the security bugs are now being exploited in the wild and has patched them in N-central 2025.3.1. It also urged admins to secure their systems before further information on the bugs is released. "Our security investigations have shown evidence of this type of exploitation in a limited number of on-premises environments. We have not seen any evidence of exploitations within N-able hosted cloud environments," N-able told BleepingComputer today. "You must upgrade your on-premises N-central to 2025.3.1. (Details of the CVEs will be published three weeks after the release as per our security practices.)," N-able added in a Wednesday advisory. While the U.S. cybersecurity agency has not yet shared details regarding the attacks exploiting these N-central security bugs, it stated that there's no evidence that they're being used in ransomware attacks. Accordin...
CISA warns of N-able N-central flaws exploited in zero-day attacks
BleepingComputer
·Sergiu Gatlan
·Published Aug 14, 2025
·Updated
Affected Software
1 affected component
N-able N-Central=2025.3.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses security vulnerabilities in N-able's N-central platform that are being actively exploited in zero-day attacks.
2
What security implications are discussed in the article?
The article highlights that attackers are successfully exploiting two critical vulnerabilities in the N-central platform, posing risks to managed services providers.
3
What specific product is affected by the vulnerabilities?
The affected product mentioned in the article is N-able N-central, specifically version 2025.3.1.
4
Who is primarily using the affected N-central platform?
The N-central platform is primarily used by managed services providers (MSPs).
5
What actions should users of N-central take in light of the vulnerabilities?
Users of N-central should implement immediate security measures and updates as recommended by CISA to mitigate the risks associated with these zero-day vulnerabilities.