Loading HuntDB...

CVE-2025-8876

UNKNOWN
Published 2025-08-14T14:53:55.176Z
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2025-8876. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

Available Exploits

No exploits available for this CVE.

Related News

Vulnerabilities in MSP-friendly RMM solution exploited in the wild (CVE-2025-8875, CVE-2025-8876)

Two vulnerabilities (CVE-2025-8875, CVE-2025-8876) in N-central, a remote monitoring and management (RMM) solution by N-able that’s popular with managed service providers, are being exploited by attackers. There are no public reports of exploitation, but the …

Help Net Security 2025-08-14 10:25
CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-8875 N-able N-central Insecure Deserialization Vulnerability CVE-2025-8876 N-able N-central C…

Cisa.gov 2025-08-13 12:00

Affected Products

Affected Versions:

Known Exploited Vulnerability

This vulnerability is actively being exploited in the wild

View KEV Details

Remediation Status

Overdue

Due Date

August 20, 2025

Added to KEV

August 13, 2025

Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Product

Vendor/Project: N-able
Product: N-Central

Ransomware Risk

Known Ransomware Use
KEV Catalog Version: 2025.08.14 Released: August 14, 2025

EU Vulnerability Database

Monitored by ENISA for EU cybersecurity

EU Coordination

EU Coordinated

Exploitation Status

No Known Exploitation

ENISA Analysis

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

Affected Products (ENISA)

n-able
n-central

ENISA Scoring

CVSS Score (4.0)

9.4
/10
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Data provided by ENISA EU Vulnerability Database. Last updated: August 14, 2025

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

⚠ Unreviewed CRITICAL

GHSA-mv58-xq9x-f6c5

Advisory Details

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

CVSS Scoring

CVSS Score

9.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Advisory provided by GitHub Security Advisory Database. Published: August 14, 2025, Modified: August 15, 2025

Social Media Intelligence

Real-time discussions and threat intelligence from social platforms

5 posts
Reddit 19 hours, 47 minutes ago
crstux
Exploit

🔥 Top 10 Trending CVEs (22/08/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2025-54336](https://nvd.nist.gov/vuln/detail/CVE-2025-54336)** - 📝 In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is 0e followed by any digit string, then an attacker can login with any …

1
1.0
View Original High Risk
Reddit 3 days, 19 hours ago
crstux
Exploit

🔥 Top 10 Trending CVEs (19/08/2025) Here’s a quick breakdown of the 10 most interesting vulnerabilities trending today: **1. [CVE-2024-42057](https://nvd.nist.gov/vuln/detail/CVE-2024-42057)** - 📝 A command injection vulnerability in the IPSec VPN feature of Zyxel ATP series firmware versions from V4.32 through V5.38, USG FLEX series firmware versions from V4.50 through V5.38, …

2
2.0
View Original High Risk
Reddit 4 days, 1 hour ago
Immediate_Gold9789

CyberDudeBivash Global Cybersecurity Brief — last 24 hours Timestamp: Tue, Aug 19, 2025 • 09:54 IST https://preview.redd.it/nddynfeolwjf1.png?width=1536&format=png&auto=webp&s=0c7e274c89f68f7a273cb8e69fd9c63a483498e0 # 1) Workday confirms CRM breach (part of ongoing Salesforce-targeting wave) **What happened:** Workday disclosed a **social-engineering** intrusion against a third-party CRM (Salesforce) that exposed business contact data; no access to customer tenants. …

Also mentions: CVE-2025-8875
Reddit 4 days, 5 hours ago
elgatomarinero

Hundreds of N-able N-central Instances Affected by Exploited Vulnerabilities Over 870 N-able N-central instances remain unpatched against critical vulnerabilities CVE-2025-8875 and CVE-2025-8876, exposing managed service providers to significant security risks despite patches issued in August - https://www.securityweek.com/hundreds-of-n-able-n-central-instances-affected-by-exploited-vulnerabilities/

Also mentions: CVE-2025-8875
19
7
33.0
Reddit 1 week, 1 day ago
_cybersecurity_
Exploit

CISA Alerts Companies of Active Exploits in N-able's Remote Management Tool **CISA warns that unpatched vulnerabilities in N-able's N-central product are being actively exploited by attackers.** **Key Points:** - CISA identified two vulnerabilities in N-able's N-central that require authentication to exploit. - The vulnerabilities, CVE-2025-8875 and CVE-2025-8876, address insecure deserialization …

Also mentions: CVE-2025-8875
5
2
9.0
View Original High Risk

References

Published: 2025-08-14T14:53:55.176Z
Last Modified: 2025-08-14T20:39:47.839Z
Copied to clipboard!