CVE-2025-8875
Insecure Deserialization Vulnerability
Description
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
In plain language
AI Act nowCVE-2025-8875 is a vulnerability in N-able N-central that can let an attacker run code on the server through local access; if you use N-central and it’s older than 2025.3.1, you should act now.
CVE-2025-8875 is an insecure deserialization (CWE-502) issue in N-able N-central that can enable local arbitrary code execution with low authentication requirements; CISA has confirmed it as exploited in the wild (KEV).
What to do now
- Check the installed N-able N-central version and confirm whether it is earlier than 2025.3.1.
- If you’re on a vulnerable version, upgrade N-able N-central to 2025.3.1 (the fixed version).
- If you cannot upgrade immediately, follow N-able’s vendor mitigations exactly as instructed for this issue and review any vendor-recommended hardening steps.
- After upgrading, verify the service is healthy and monitor N-central/admin access logs for suspicious activity consistent with compromise.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flawen·The Hacker News· Exploited N-central rce
- N-able patches max severity N-central flaw amid ongoing attacksen-us·BleepingComputer· Exploited N-able N-central rce
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesen·The Hacker News· Exploited N-able N-central supply-chain
- Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)en-us·Help Net Security· Exploited N-able N-central supply-chain
- N‑able Patches Vulnerability Exploited to Hack N-central Serversen-us·SecurityWeek· Exploited N-able N-central supply-chain
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-8875 and every CVE in our database. Create a free account — no credit card required.
Create Free Account