CVE-2025-8876
Command Injection Vulnerability
Description
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
In plain language
AI Act nowCVE-2025-8876 is a flaw in N-able N-central (before 2025.3.1) that can let attackers run commands on your server over the network, and it’s already been exploited—so you should treat it as urgent and upgrade.
CVE-2025-8876 is an OS command injection in N-able N-central (pre-2025.3.1) caused by improper input validation; attackers can reach the vulnerable network-facing functionality with low authentication needs and execute arbitrary operating system commands.
What to do now
- Check your N-able N-central version and confirm whether it is earlier than 2025.3.1.
- Upgrade N-able N-central to 2025.3.1 (or later) as the fix for CVE-2025-8876.
- If you cannot upgrade immediately, follow N-able vendor mitigation instructions for this issue and restrict network access to N-central per those directions.
- If you suspect compromise, revoke affected admin access and rotate credentials on N-central and any managed endpoints, then restore from known-good backups if needed.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flawen·The Hacker News· Exploited N-central rce
- N-able patches max severity N-central flaw amid ongoing attacksen-us·BleepingComputer· Exploited N-able N-central rce
- CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromisesen·The Hacker News· Exploited N-able N-central supply-chain
- Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577)en-us·Help Net Security· Exploited N-able N-central supply-chain
- N‑able Patches Vulnerability Exploited to Hack N-central Serversen-us·SecurityWeek· Exploited N-able N-central supply-chain
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-8876 and every CVE in our database. Create a free account — no credit card required.
Create Free Account