← Vulnerability feed

Vulnerability record · CVE-2025-8875 · published 14 August 2025

CVE-2025-8875: N-able N-central deserialization of untrusted data allows code execution

N Able · N Central

N-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3.1, and the vendor released a fixed build. Because N-central is remote monitoring and management software, a compromise can expose managed endpoints and customer environments.

9.4 CVSS 4.0 Critical CISA KEV since 13 Aug 2025 EPSS 1.9% · top 21.2% CWE-502 · Deserialization of untrusted data
9.4CVSS 4.0 base score
1.9%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
2References
24 Sep 2026Last modified by NVD

Description

Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score is 9.4 (critical) and the flaw is in CISA KEV with known exploitation, so it warrants immediate remediation.

What it is

N-able N-central contains a deserialization of untrusted data flaw (CWE-502) that permits code execution. It affects N-central versions before 2025.3.1, and the vendor released a fixed build. Because N-central is remote monitoring and management software, a compromise can expose managed endpoints and customer environments.

Impact

An attacker who can reach the vulnerable deserialization path can execute code in the context of the N-central service, with high impact to confidentiality, integrity and availability of both the vulnerable system and connected systems.

Attack surface

The CVSS 4.0 vector is network reachable (AV:N) with low privileges required (PR:L) and no user interaction (UI:N), so an authenticated low-privileged user can trigger it remotely. No pre-authentication path is indicated by the record.

Exploitation

CVE-2025-8875 is listed in CISA KEV with a due date of 2025-08-20, indicating known exploitation in the wild. EPSS 30-day probability is 0.01721 (76th percentile), and no ransomware campaign use is documented.

What to do

  • Upgrade N-central to 2025.3.1 or later per the vendor release notes.
  • If immediate patching is not possible, apply the vendor mitigations referenced in the CISA KEV entry or discontinue use of the product.
  • Restrict network access to the N-central management interface to trusted administrative networks.
  • Review and reduce accounts with access to N-central, removing unnecessary low-privileged users.
  • Monitor for post-exploitation activity on N-central hosts and connected managed endpoints.

Detection

  • Hunt for unexpected child processes spawned by the N-central service or its application server.
  • Review N-central and host logs for deserialization errors, unusual object payloads, or anomalous requests to management endpoints.
  • Audit authentication and administrative activity for new or unexpected accounts and privilege changes.
  • Check for outbound connections from N-central hosts to unfamiliar external addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-8875 to the Known Exploited Vulnerabilities catalog on 13 August 2025 as "N-able N-Central Insecure Deserialization Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 20 August 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-8875 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-86218N-able N-central pre-auth remote code execution via static code injectionN-central contains a static code injection flaw (CWE-96) that allows remote code execution before authentication. The record states the issue affects…KEVEPSS 13%analysed9.4CVE-2025-8876N-able N-central improper input validation leads to OS command injectionN-able N-central before 2025.3.1 fails to properly validate input, allowing OS command injection. Because N-central is a remote monitoring and manage…KEVEPSS 3.4%analysed8.2CVE-2026-18577N-able N-central incomplete patch enables auth bypass and account takeoverAn incomplete fix for CVE-2026-18556 leaves an alternate-path authentication bypass in N-able N-central through version 2026.3.1. Because the origina…KEVEPSS 15%analysed8.2CVE-2026-18556N-able N-central authentication bypass via alternate pathN-able N-central contains an authentication bypass (CWE-288) that lets an attacker reach protected functionality through an alternate path or channel…KEVEPSS 7.9%analysed10.0CVE-2025-11367N-able n-central deserialization of untrusted data vulnerabilityThe N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserializationEPSS 0.58%9.8CVE-2024-28200N-able n-central authentication bypass via alternate path vulnerabilityThe N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central p…EPSS 1.9%9.8CVE-2023-47132N-able n-central improper privilege management vulnerabilityAn issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.EPSS 0.55%9.4CVE-2025-11366N-able n-central path traversal vulnerabilityN-central < 2025.4 is vulnerable to authentication bypass via path traversalEPSS 0.56%

Source: NIST National Vulnerability Database (record CVE-2025-8875), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.