Vulnerabilities

Summary — last 7 days

New vulnerabilities3,351▲ 378 vs. last week
Critical / high1,495▲ 137 vs. last week
New active exploitation (KEV)7▼ 3 vs. last week
Unscored (no CVSS)592▲ 120 vs. last week
–

28 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedCritical (10)13%⚠ Active exploitationN-able N-central9/6/20269/9/2026
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Awaiting AnalysisMedium (6.9)1.1%—N-centralAI9/5/20269/8/2026
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Awaiting AnalysisHigh (7.7)1.3%—N-able N-centralAI9/5/20269/8/2026
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
AnalyzedHigh (8.2)15%⚠ Active exploitationN-able N-central8/2/20268/4/2026
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
AnalyzedHigh (8.2)7.9%⚠ Active exploitationN-able N-central8/1/20268/5/2026
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
DeferredMedium (6.9)36%—N-able N-centralAI11/12/20256/17/2026
N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
ModifiedHigh (8.4)31%—N-able N-central11/12/20256/17/2026
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
AnalyzedCritical (10)0.58%—N-able N-central11/12/20256/17/2026
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
AnalyzedCritical (9.4)0.56%—N-able N-central11/12/20256/17/2026
N-central < 2025.4 is vulnerable to authentication bypass via path traversal
AnalyzedHigh (7.8)0.13%—N-able N-central9/10/20259/26/2026
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.
AnalyzedHigh (8.3)0.28%—N-able N-central8/21/20256/17/2026
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
AnalyzedCritical (9.4)3.4%⚠ Active exploitationN-able N-central8/14/20256/17/2026
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
AnalyzedCritical (9.4)1.9%⚠ Active exploitationN-able N-central8/14/20259/24/2026
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
AnalyzedMedium (5.3)0.40%—N-able N-central3/17/20256/17/2026
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
AnalyzedCritical (9.1)0.41%—N-able N-central7/1/20246/17/2026
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
ModifiedCritical (9.8)1.9%—N-able N-central7/1/20246/17/2026
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
ModifiedCritical (9.8)0.55%—N-able N-central2/8/20246/17/2026
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
ModifiedHigh (7)0.18%—N-able N-central8/4/20236/17/2026
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.
ModifiedHigh (8.8)0.96%—Solarwinds N-central12/16/20206/17/2026
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows CSRF.
ModifiedHigh (8.4)0.54%—Solarwinds N-central12/16/20206/17/2026
An issue was discovered in SolarWinds N-Central 12.3.0.670. The local database does not require authentication: security is only based on ability to access a network interface. The database has keys and passwords.
ModifiedHigh (7.8)0.43%—Solarwinds N-central12/16/20206/17/2026
An issue was discovered in SolarWinds N-Central 12.3.0.670. Hard-coded Credentials exist by default for local user accounts named support@n-able.com and nableadmin@n-able.com. These allow logins to the N-Central Administrative Console (NAC) and/or the regular web interface.
ModifiedMedium (4.4)0.45%—Solarwinds N-central12/16/20206/17/2026
An issue was discovered in SolarWinds N-Central 12.3.0.670. The SSH component does not restrict the Communication Channel to Intended Endpoints. An attacker can leverage an SSH feature (port forwarding with a temporary key pair) to access network services on the 127.0.0.1 interface, even though this feature was only…
ModifiedHigh (8.8)2.7%—Solarwinds N-central12/16/20206/17/2026
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).
ModifiedHigh (8.8)3.3%—Solarwinds N-central12/16/20206/17/2026
An issue was discovered in SolarWinds N-Central 12.3.0.670. The AdvancedScripts HTTP endpoint allows Relative Path Traversal by an authenticated user of the N-Central Administration Console (NAC), leading to execution of OS commands as root.
ModifiedMedium (4.7)5.6%—Solarwinds N-central10/19/20206/17/2026
SolarWinds N-Central version 12.3 GA and lower does not set the JSESSIONID attribute to HTTPOnly. This makes it possible to influence the cookie with javascript. An attacker could send the user to a prepared webpage or by influencing JavaScript to the extract the JESSIONID. This could then be forwarded to the attacker.