Over 800 N-able N-central servers remain unpatched against a pair of critical security vulnerabilities tagged as actively exploited last week. N-central is a popular platform used by many managed services providers (MSPs) and IT departments to monitor and manage networks and devices from a centralized web-based console. Tracked as CVE-2025-8875 and CVE-2025-8876, the two flaws can let authenticated attackers to inject commands due to improper sanitization of user input and execute commands on unpatched devices by exploiting an insecure deserialization weakness, respectively. N-able has patched them in N-central 2025.3.1 and told BleepingComputer on Thursday that the security bugs are now under active exploitation, urging admins to secure their servers before further information on the bugs is released. "Our security investigations have shown evidence of this type of exploitation in a limited number of on-premises environments. We have not seen any evidence of exploitation within N-able hosted cloud environments," N-able told BleepingComputer. "You must upgrade your on-premises N-central to 2025.3.1. (Details of the CVEs will be published three weeks after the release as per our security practices.)," N-able added in a Wednesday advisory. On Friday, the internet security nonprofit Shadowserver Foundation is tracking 880 N-central servers that are still vulnerable to attacks exploiting the two vulnerabilities, most of them located in the United States, Canada, and the Netherla...
Over 800 N-able servers left unpatched against critical flaws
BleepingComputer
·Sergiu Gatlan
·Published Aug 18, 2025
·Updated
Affected Software
1 affected component
N-able N-Central=2025.3.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery that over 800 N-able N-central servers are unpatched against critical security vulnerabilities.
2
What critical security vulnerabilities are highlighted?
The article emphasizes that the vulnerabilities are actively exploited and pose significant risks to N-able N-central servers.
3
Which software product is specifically affected by these vulnerabilities?
The affected software product is N-able N-central, specifically version 2025.3.1.
4
Who are the primary users of the N-able N-central platform?
N-able N-central is primarily used by managed service providers (MSPs) and IT departments.
5
What actions should affected users take in response to this article?
Affected users should prioritize patching their N-able N-central servers to mitigate the risks associated with the identified vulnerabilities.