CVE-2025-8876: N-able N-Central Command Injection Vulnerability

High severity, CVSS 8.8. Actively exploited: in CISA KEV since 2025-08-13. EPSS: 3.4% chance of exploitation in the next 30 days.

Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.

Affected products

  • N-able N-central: before 2025.3.1 (fixed in 2025.3.1)

Published 2025-08-14. Last modified 2026-06-17.