• News/
  • https://www.bleepingcomputer.com/news/security/cisa-warns-of-n-able-n-central-flaws-exploited-in-zero-day-attacks/

CISA warns of N-able N-central flaws exploited in zero-day attacks

BleepingComputer
·
Sergiu Gatlan
·
Published Aug 14, 2025
·
Updated

​CISA warned on Wednesday that attackers are actively exploiting two security vulnerabilities in N‑able's N-central remote monitoring and management (RMM) platform. N-central is commonly used by managed services providers (MSPs) and IT departments to monitor, manage, and maintain client networks and devices from a centralized web-based console. According to CISA, the two flaws can allow authenticated attackers to gain command execution via an insecure deserialization weakness (CVE-2025-8875) and inject commands by exploiting an improper sanitization of user input vulnerability (CVE-2025-8876). N-able confirms CISA's report that the security bugs are now being exploited in the wild and has patched them in N-central 2025.3.1. It also urged admins to secure their systems before further information on the bugs is released. "Our security investigations have shown evidence of this type of exploitation in a limited number of on-premises environments. We have not seen any evidence of exploitations within N-able hosted cloud environments," N-able told BleepingComputer today. "You must upgrade your on-premises N-central to 2025.3.1. (Details of the CVEs will be published three weeks after the release as per our security practices.)," N-able added in a Wednesday advisory. While the U.S. cybersecurity agency has not yet shared details regarding the attacks exploiting these N-central security bugs, it stated that there's no evidence that they're being used in ransomware attacks. Accordin...

Read full article

Affected Software

1 affected component
N-able N-Central=2025.3.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses security vulnerabilities in N-able's N-central platform that are being actively exploited in zero-day attacks.

2

What security implications are discussed in the article?

The article highlights that attackers are successfully exploiting two critical vulnerabilities in the N-central platform, posing risks to managed services providers.

3

What specific product is affected by the vulnerabilities?

The affected product mentioned in the article is N-able N-central, specifically version 2025.3.1.

4

Who is primarily using the affected N-central platform?

The N-central platform is primarily used by managed services providers (MSPs).

5

What actions should users of N-central take in light of the vulnerabilities?

Users of N-central should implement immediate security measures and updates as recommended by CISA to mitigate the risks associated with these zero-day vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CISA warns of N-able N-central flaws exploited in zero-day attacks - SecAlerts