N-able
N-able N-central: vulnerabilities and CVEs
N-able N-central has 17 published vulnerabilities, 8 of them in the last 12 months. 8 are rated critical and 5 are listed by CISA as actively exploited.
CVEs17
Last 12 months8
Critical8
Actively exploited5
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86218 | Critical (10) | 13% | ⚠ Active exploitation | Sep 6, 2026 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-18556 | High (8.2) | 7.9% | ⚠ Active exploitation | Aug 1, 2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. |
| CVE-2026-18577 | High (8.2) | 15% | ⚠ Active exploitation | Aug 2, 2026 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 |
| CVE-2025-8875 | Critical (9.4) | 1.9% | ⚠ Active exploitation | Aug 14, 2025 | Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. |
| CVE-2025-8876 | Critical (9.4) | 3.4% | ⚠ Active exploitation | Aug 14, 2025 | Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86218 | Critical (10) | 13% | ⚠ Active exploitation | Sep 6, 2026 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-86207 | High (7.7) | 1.3% | — | Sep 5, 2026 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs |
| CVE-2026-18577 | High (8.2) | 15% | ⚠ Active exploitation | Aug 2, 2026 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 |
| CVE-2026-18556 | High (8.2) | 7.9% | ⚠ Active exploitation | Aug 1, 2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. |
| CVE-2025-9316 | Medium (6.9) | 36% | — | Nov 12, 2025 | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. |
| CVE-2025-11700 | High (8.4) | 31% | — | Nov 12, 2025 | N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure |
| CVE-2025-11367 | Critical (10) | 0.58% | — | Nov 12, 2025 | The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization |
| CVE-2025-11366 | Critical (9.4) | 0.56% | — | Nov 12, 2025 | N-central < 2025.4 is vulnerable to authentication bypass via path traversal |
| CVE-2025-10231 | High (7.8) | 0.13% | — | Sep 10, 2025 | An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions. |
| CVE-2025-7051 | High (8.3) | 0.28% | — | Aug 21, 2025 | On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to… |
| CVE-2025-8876 | Critical (9.4) | 3.4% | ⚠ Active exploitation | Aug 14, 2025 | Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. |
| CVE-2025-8875 | Critical (9.4) | 1.9% | ⚠ Active exploitation | Aug 14, 2025 | Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. |
| CVE-2024-8510 | Medium (5.3) | 0.40% | — | Mar 17, 2025 | N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to… |
| CVE-2024-5322 | Critical (9.1) | 0.41% | — | Jul 1, 2024 | The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of… |
| CVE-2024-28200 | Critical (9.8) | 1.9% | — | Jul 1, 2024 | The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal… |
| CVE-2023-47132 | Critical (9.8) | 0.55% | — | Feb 8, 2024 | An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls. |
| CVE-2023-30297 | High (7) | 0.18% | — | Aug 4, 2023 | An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.